Open Handbooknpm: rea-agents • Reverse Engineer Anything

How to REA: <span class="text-sky-400">Reverse Engineer Anything</span> (rea-agents)

AI Overview Direct AnswerREA (Reverse Engineer Anything)

REA (Reverse Engineer Anything, distributed as rea-agents on npm by morluto) is the open-source Model Context Protocol (MCP) server connecting AI coding agents—such as Claude Code, Cursor, Codex, and Gemini CLI—to application runtimes, Hopper/Ghidra/IDA native disassemblers, Electron bundles, and Android APKs to extract architecture and build features without source code.

87,000+
GitHub Stars (morluto/rea)
689 pts
Hacker News Frontpage
v6.4.0
Verified NPM Package
29 Tools
Ecosystem Directory
ℹ
Community Documentation Companionhowtorea.com is an independent community documentation handbook for REA (Reverse Engineer Anything). While the official project lives at morluto/rea and rea.tools, this handbook provides interactive MCP generators for 12+ agents, 29 deep-dive tool guides, and clean-room deconstruction specifications.

01.3-Minute Quickstart

Configure your AI coding agent (Claude Code, Cursor, Codex) in one automated step using the official setup script:

One-Step Agent Setup
npx rea-agents setup

Or run direct terminal inspection on any JavaScript / Electron application or native binary:

Ad-hoc Terminal Inspection
# Inspect an Electron or JavaScript app directory/ASAR
npx -y rea-agents@latest analyze-javascript-application /path/to/app --json

# Or install globally for regular use
npm install --global rea-agents
rea --help

02.What is REA & How Does It Work?

Traditional reverse engineering tools like IDA Pro, Ghidra, or Hopper produce raw assembly and decompiled C output that requires hours of manual interpretation. REA fundamentally reimagines this workflow by placing an <strong>AI Coding Agent at the center of runtime inspection</strong>.

Traditional Decompilers
  • Manual CFG graph traversal
  • Low-level register tracking
  • No semantic context understanding
  • Hours spent labeling symbols
REA + Agentic Workflow
  • Agent inspects AST & binary exports
  • Translates raw structures into clean models
  • Automated MCP tool invocation via Claude
  • Produces clean-room TypeScript / Rust specs

03.Runtime Architecture Model

REA operates through a decoupled dual-ring architecture: the CLI probe handles sandboxed system-level extraction, while the MCP server exposes standardized tool endpoints to LLM coding agents:

  +-------------------------------------------------------------+
  |              AI Agent Client (Claude / Cursor)              |
  +-------------------------------------------------------------+
                               |
                   [JSON-RPC via stdio / SSE]
                               v
  +-------------------------------------------------------------+
  |                   REA MCP Server Service                    |
  +-------------------------------------------------------------+
         |                       |                       |
         v                       v                       v
  [Electron Unpacker]   [Native Symbol Probe]   [Network Schema Sniffer]
         |                       |                       |
         v                       v                       v
  app.asar JS Bundle      Mach-O / PE Exports      Private WebSocket API

Explore by Topic