Getting Started with REA: Reverse Engineer Anything
REA (Reverse Engineer Anything) is distributed via the official rea-agents package on npm. With a single command (npx rea-agents setup), it automatically configures Claude Code, Cursor, Codex, or Gemini CLI with the REA Model Context Protocol (MCP) server, analysis instructions, and optional native decompiler bridges (Hopper, Ghidra, IDA).
Prerequisites
Before running REA, verify that your local environment satisfies the runtime requirements:
- Node.js Environment:Node.js v22.x (>=22.19), v24.x, or v26+, with npm (or Bun v1.2.17+)
- AI Agent Client:Claude Code, Cursor IDE, Codex, Gemini CLI, or Grok Build
- Native Decompilers (Optional for Native Binaries):Hopper Disassembler, Ghidra, or IDA Pro (static JavaScript & Electron analysis requires no native decompiler)
- Operating Systems:macOS (Apple Silicon & Intel), Linux x64/ARM64, Windows 10/11
Installation & Setup
Method 1: Automated Agent Setup (Recommended)
Run the official interactive agent setup script to register the REA MCP server across your coding agents:
npx rea-agents setupMethod 2: Global CLI Installation
Install the persistent <code>rea</code> command for regular terminal analysis:
# Install globally via npm
npm install --global rea-agents
# Or via Bun
bun add --global rea-agents
# Verify CLI readiness
rea --help
# Keep installation up to date
rea updateMethod 3: Ad-hoc Electron & JavaScript Inspection
Inspect an unpacked application or .asar archive on-demand without installing anything globally:
npx -y rea-agents@latest analyze-javascript-application /path/to/app --jsonMethod 4: Skill-Only Agent Installation (skills.sh)
If you only need agent prompt instructions and workflow reasoning without installing local disassemblers:
npx skills add morluto/rea --skill reverse-engineer-anythingSupported Targets (What You Can Analyze)
REA provides specialized extraction pipelines across 14 target categories. Static JavaScript and .NET analysis run 100% locally with zero external decompiler dependencies, while native and mobile targets leverage dedicated bridges:
| Target Ecosystem | What REA Returns | Engine & Prerequisites |
|---|---|---|
| Native Binaries | Pseudocode, assembly instructions, strings, symbols, call graphs & cross-references | Hopper, Ghidra, or IDA Pro |
| JavaScript / Electron | Modules, imports, source maps, routes, IPC boundaries and native add-on links | Node.js 22+ & npm (Zero native engine needed) |
| .NET Assemblies | Metadata, CIL instructions, declared native dependencies & build comparisons | Built-in static PE/CLI parser |
| Android APKs | Manifest declarations, Java/Kotlin classes, decompiled methods & references | Headless JADX & JDK |
| Android Devices | Connected devices, packages, processes, dumps, screen captures & transfers | Caller-supplied adb (Hardware or Emulator) |
| Android Resources | Decoded AndroidManifest.xml, string tables, locales & version facts | Apktool launcher |
| EVM Bytecode | Dispatch selectors, byte offsets, inferred arguments & contract mutability | Built-in EVMole WASM engine |
| Firmware Images | Memory regions, extraction results & native analysis handoffs | Binwalk / Unblob on Linux |
| Websites | DOM structure, scripts, network observations & full-page screenshots | Chrome-family browser via CDP |
| Network Captures | HTTP requests, responses, exposed JSON payloads & source locations | HAR or mitmdump on Linux |
| Offline ELF Layout | Sections, segments, original symbols, relocations & mitigation flags | pwntools on Linux x64 |
| Linux Crashes | Registers, signals, core thread dumps & optional mapping candidates | pwntools & GDB / pwndbg |
| Apple Packages | File inventories, digests, plists, Apple bundle anatomy & resources | Built-in Mach-O / plist parser |
| Process Behavior | Terminal interactions, exit statuses, filesystem changes & runtime diffs | Linux / macOS native PTY |
CLI Command Reference
The core REA binary accepts the following flags for ad-hoc inspection and MCP server hosting:
| Flag | Type | Default | Description |
|---|---|---|---|
--mcp | Boolean | false | Launches REA in Model Context Protocol stdio server mode for Claude/Cursor. |
--target, -t | Path | . | Target executable binary, .app bundle, or .asar file to introspect. |
--format, -f | String | json | Output serialization: json, ast, typescript, or rust. |
--depth, -d | Integer | 3 | Maximum traversal depth for dependency resolution and export tracing. |
--clean-room | Boolean | true | Sanitizes proprietary bytecode and extracts only abstract interface schemas. |
Verify CLI Environment
Run the healthcheck command to verify that REA and its underlying introspection engines are operational:
rea --version
rea doctorExpected diagnostic output:
{
"rea_version": "0.4.2",
"node_runtime": "v20.12.0",
"mcp_protocol": "2024-11-05",
"supported_targets": ["electron-asar", "macho-universal", "pe32-pe64", "elf64"],
"status": "READY"
}