Chapter 01Installation & Prerequisites

Getting Started with REA: Reverse Engineer Anything

AI Overview Direct AnswerInstalling & Setting Up REA (rea-agents)

REA (Reverse Engineer Anything) is distributed via the official rea-agents package on npm. With a single command (npx rea-agents setup), it automatically configures Claude Code, Cursor, Codex, or Gemini CLI with the REA Model Context Protocol (MCP) server, analysis instructions, and optional native decompiler bridges (Hopper, Ghidra, IDA).

Prerequisites

Before running REA, verify that your local environment satisfies the runtime requirements:

  • Node.js Environment:Node.js v22.x (>=22.19), v24.x, or v26+, with npm (or Bun v1.2.17+)
  • AI Agent Client:Claude Code, Cursor IDE, Codex, Gemini CLI, or Grok Build
  • Native Decompilers (Optional for Native Binaries):Hopper Disassembler, Ghidra, or IDA Pro (static JavaScript & Electron analysis requires no native decompiler)
  • Operating Systems:macOS (Apple Silicon & Intel), Linux x64/ARM64, Windows 10/11

Installation & Setup

Method 1: Automated Agent Setup (Recommended)

Run the official interactive agent setup script to register the REA MCP server across your coding agents:

One-Step Agent Setup
npx rea-agents setup

Method 2: Global CLI Installation

Install the persistent <code>rea</code> command for regular terminal analysis:

Global CLI Install & Update
# Install globally via npm
npm install --global rea-agents

# Or via Bun
bun add --global rea-agents

# Verify CLI readiness
rea --help

# Keep installation up to date
rea update

Method 3: Ad-hoc Electron & JavaScript Inspection

Inspect an unpacked application or .asar archive on-demand without installing anything globally:

Ad-hoc Analysis
npx -y rea-agents@latest analyze-javascript-application /path/to/app --json

Method 4: Skill-Only Agent Installation (skills.sh)

If you only need agent prompt instructions and workflow reasoning without installing local disassemblers:

Install Agent Skill
npx skills add morluto/rea --skill reverse-engineer-anything

Supported Targets (What You Can Analyze)

REA provides specialized extraction pipelines across 14 target categories. Static JavaScript and .NET analysis run 100% locally with zero external decompiler dependencies, while native and mobile targets leverage dedicated bridges:

Target EcosystemWhat REA ReturnsEngine & Prerequisites
Native BinariesPseudocode, assembly instructions, strings, symbols, call graphs & cross-referencesHopper, Ghidra, or IDA Pro
JavaScript / ElectronModules, imports, source maps, routes, IPC boundaries and native add-on linksNode.js 22+ & npm (Zero native engine needed)
.NET AssembliesMetadata, CIL instructions, declared native dependencies & build comparisonsBuilt-in static PE/CLI parser
Android APKsManifest declarations, Java/Kotlin classes, decompiled methods & referencesHeadless JADX & JDK
Android DevicesConnected devices, packages, processes, dumps, screen captures & transfersCaller-supplied adb (Hardware or Emulator)
Android ResourcesDecoded AndroidManifest.xml, string tables, locales & version factsApktool launcher
EVM BytecodeDispatch selectors, byte offsets, inferred arguments & contract mutabilityBuilt-in EVMole WASM engine
Firmware ImagesMemory regions, extraction results & native analysis handoffsBinwalk / Unblob on Linux
WebsitesDOM structure, scripts, network observations & full-page screenshotsChrome-family browser via CDP
Network CapturesHTTP requests, responses, exposed JSON payloads & source locationsHAR or mitmdump on Linux
Offline ELF LayoutSections, segments, original symbols, relocations & mitigation flagspwntools on Linux x64
Linux CrashesRegisters, signals, core thread dumps & optional mapping candidatespwntools & GDB / pwndbg
Apple PackagesFile inventories, digests, plists, Apple bundle anatomy & resourcesBuilt-in Mach-O / plist parser
Process BehaviorTerminal interactions, exit statuses, filesystem changes & runtime diffsLinux / macOS native PTY

CLI Command Reference

The core REA binary accepts the following flags for ad-hoc inspection and MCP server hosting:

FlagTypeDefaultDescription
--mcpBooleanfalseLaunches REA in Model Context Protocol stdio server mode for Claude/Cursor.
--target, -tPath.Target executable binary, .app bundle, or .asar file to introspect.
--format, -fStringjsonOutput serialization: json, ast, typescript, or rust.
--depth, -dInteger3Maximum traversal depth for dependency resolution and export tracing.
--clean-roomBooleantrueSanitizes proprietary bytecode and extracts only abstract interface schemas.

Verify CLI Environment

Run the healthcheck command to verify that REA and its underlying introspection engines are operational:

Verify Installation
rea --version
rea doctor

Expected diagnostic output:

Output: rea doctor
{
  "rea_version": "0.4.2",
  "node_runtime": "v20.12.0",
  "mcp_protocol": "2024-11-05",
  "supported_targets": ["electron-asar", "macho-universal", "pe32-pe64", "elf64"],
  "status": "READY"
}