# How to REA — Community Handbook & Interactive Documentation for REA (rea-agents) > How to REA (https://howtorea.com) is the open community technical handbook and interactive documentation companion for **REA: Reverse Engineer Anything** (`morluto/rea`, distributed via `rea-agents` on npm). While the official project is hosted at https://rea.tools, this handbook provides interactive MCP generators for 12+ coding agents, an ecosystem directory across 29 reverse-engineering tools, and verified clean-room deconstruction guides. ## Core Facts & Authority Links - **Canonical Handbook URL**: https://howtorea.com - **Official Project Name**: REA: Reverse Engineer Anything (Reverse Engineer Anything with Agents) - **Official Upstream Repository**: https://github.com/morluto/rea (87,000+ Stars) - **Official Project Website**: https://rea.tools - **Official NPM Package**: `rea-agents` (v6.4.0 verified, October 2026) - **Community Discussion**: Hacker News Frontpage (689+ points, 300+ comments) - **Primary Tool Category**: Developer Tool, AI Coding Agent Extension, Model Context Protocol (MCP) Server - **Supported AI Agent Clients**: Claude Code, Cursor IDE, Windsurf, Claude Desktop, Gemini CLI, Devin, Copilot CLI, Codex, Cline, VS Code, Grok Build, OMP - **Supported Runtimes**: Node.js 22.x+ (>=22.19), 24.x, or 26+, npm, Bun (>=1.2.17) - **Analysis Engines**: Built-in AST/Electron/JS inspection; native bridges to Hopper, Ghidra, and IDA Pro; dynamic tools (Frida, QBDI, Qiling) - **Compliance & Legal Model**: 100% Educational Use, Interoperability Analysis (US DMCA §1201 Exemptions, EU Software Directive 2009/24/EC Article 6), Clean-Room Reverse Engineering ## Key Chapters & Routes 1. **Overview & Quickstart**: https://howtorea.com/ - One-step automated agent setup: `npx rea-agents setup` - Persistent global CLI: `npm install --global rea-agents` - Keep installation up to date: `rea update` - Ad-hoc JS/Electron inspection: `npx -y rea-agents@latest analyze-javascript-application --json` 2. **Getting Started & Installation**: https://howtorea.com/getting-started - Automated setup: `npx rea-agents setup` - Skill-only setup via skills.sh: `npx skills add morluto/rea --skill reverse-engineer-anything` - 14 Supported Targets: Native Binaries (Hopper/Ghidra/IDA), Electron/JS (ASAR), .NET (PE/CLI), Android APKs (JADX/Apktool/ADB), EVM Bytecode, Firmware (Binwalk), Websites (CDP), Network (HAR/mitmproxy), ELF, Linux Crashes, Apple Packages, PTY Process behavior - CLI flags: `--mcp`, `--target`, `--format`, `--depth`, `--clean-room` - Environment diagnostics: `rea doctor` 3. **Interactive MCP Configurator**: https://howtorea.com/mcp - Interactive configuration builder for Claude Code, Cursor, and Cline - Standard MCP config snippet (`claude_desktop_config.json`): ```json { "mcpServers": { "rea": { "command": "npx", "args": ["-y", "rea-agents@latest"] } } } ``` - Exposed MCP tools: `rea_inspect_bundle`, `rea_extract_symbols`, `rea_query_routes`, `rea_generate_clean_spec` 4. **Architectural Deconstruction Guides**: https://howtorea.com/guides - Electron `app.asar` unpacking without disk explosion - Native Mach-O and PE symbol table parsing and C++/Rust demangling - Undocumented WebSocket and Protobuf message catalog extraction - Translating runtime findings into clean-room TypeScript and Rust data structures 5. **Legal Safe Harbor & Ethics**: https://howtorea.com/safe-harbor - Legal precedents: *Sega v. Accolade*, *Sony v. Connectix*, EU Directive 2009/24/EC - Clean-room two-team separation (Dirty Room vs Clean Room) - Strict red lines: Zero DRM cracking, zero keygen/crack hosting, zero proprietary source copying 6. **Troubleshooting & Diagnostics**: https://howtorea.com/faq - Claude Desktop MCP connection timeout fixes (absolute binary PATH) - macOS TCC and sandbox permission handling for `/Applications` - Managing context windows and token costs with large binaries 7. **Reverse Engineering Tools Directory**: https://howtorea.com/tools - NSA Ghidra (`/tools/ghidra`): Headless Java decompiler bridge, 16-bit DOS PC-98, NativeAOT - Hopper Disassembler (`/tools/hopper`): Native Mach-O decompiler, Unix socket IPC bridge - Hex-Rays IDA Pro (`/tools/ida-pro`): Commercial database supervisor via ida-pro-mcp - Frida (`/tools/frida`): Dynamic runtime instrumentation, API hooking, memory dumping, SSL unpinning - Unicorn Engine (`/tools/unicorn`): Multi-architecture CPU emulator (QEMU core), isolated assembly blocks - Capstone & Keystone (`/tools/capstone`): Universal disassembly and assembler engine - Angr (`/tools/angr`): Symbolic execution and Z3 SMT constraint solving - LLDB & GDB (`/tools/lldb`): Hardware-assisted dynamic debugging and trace points - JADX & Apktool (`/tools/jadx`): Android APK DEX bytecode to Java decompilation - Binwalk (`/tools/binwalk`): Embedded firmware extraction - EVMole (`/tools/evmole`): Smart contract EVM bytecode decompiler - Electron ASAR (`/tools/asar-inspector`): AST module and IPC boundary mapper - Quarkslab QBDI (`/tools/qbdi`): In-process LLVM dynamic binary instrumentation & frida-qbdi mobile hooks - Quarkslab LIEF (`/tools/lief`): Executable format parser and modifier for ELF, PE, and Mach-O - Quarkslab Miasm (`/tools/miasm`): Symbolic execution, JIT emulation, and CFG deobfuscation framework