Repo of the Day
morluto/rea
Published: Oct 6, 2026
Open repository ↗Reverse engineer anything with agents, from app behavior down to native binaries
Summary
REA is a TypeScript-based MCP server and CLI that connects AI coding agents to reverse-engineering tools for inspecting native binaries, JavaScript/Electron apps, .NET assemblies, and websites. It exposes local analysis through Hopper or Ghidra, letting an agent walk from clues like strings and procedures to decompiled pseudocode. Analysis runs on the user's host, and each result is returned alongside its evidence and stated limitations.
What it is useful for
REA is useful when an engineer wants to understand how an existing app implements a feature without source code. Concrete cases called out in the README include tracing offline search inside macOS Notes, reconstructing authentication or update flows, recovering undocumented formats, mapping .NET CIL instructions, comparing two builds, and capturing controlled process behavior for diffing. It also supports CTF-style work, Swift and Objective-C demangling, and passive browser observation through a loopback CDP endpoint.
How engineers can use it
On macOS or supported Linux distributions (Ubuntu 24.04+, Fedora 41+, 64-bit Arch), install Node.js 22.19+, 24.11+, or 26+ and run npx rea-agents setup. Setup selects which supported agents gain MCP access, optionally installs Hopper in ~/Applications with consent, or records an existing Ghidra 12.1.4 install plus a 64-bit JDK 21. After restarting the agent, a prompt like "Reverse engineer the Notes app. Find how offline search works" drives a six-step investigation: open_binary, then search_strings/search_procedures, then find_xrefs_to_name, then get_call_graph/procedure_callees, then procedure_pseudo_code, then the agent builds code for the user's own project.
From the terminal, the same capabilities are available: npx -y rea-agents@latest analyze /Applications/Notes.app for a one-shot look, or rea analyze PATH after npm install --global rea-agents. Snapshot files via --snapshot reuse immutable results across sessions, and rea evidence-import, rea evidence-export, and rea compare validate and diff Evidence bundles. Run npx -y rea-agents@latest doctor to check the host and agent configuration without changing anything.
The README is explicit about scope. Decompilation produces pseudocode rather than original source. Dynamic and ambiguous relationships in JavaScript/Electron stays unresolved. Windows Ghidra support is experimental for read-only native x86-64 PE on local NTFS. Hopper-only GUI controls and bookmarking are not exposed via Ghidra. Engineers should consult docs/installation.md and docs/provider-evaluation.md in the repository for setup details and verified scope on their host.