Mobile & App SecurityCLI Flag: --provider javascript

Electron ASAR & JS Graphin REA

Direct AST projection, ASAR directory traversal, and IPC channel mapping without source.

AI Overview Direct AnswerElectron ASAR & JS Graph Integration in REA

In REA (rea-agents), Electron ASAR & JS Graph is integrated via --provider javascript to enable AI coding agents to inspect application binaries, extract symbol tables, generate pseudocode, and trace execution boundaries without source code.

Supported Platforms & Targets

Host Operating Systems:
macOSLinuxWindows
Target Architectures:
Electron app.asarNode.js ModulesWebpack / Vite Chunks

Tool Overview & Role

REA's built-in static JavaScript and Electron engine requires zero native decompilers. It parses concatenated app.asar archives, reconstructs module dependencies, resolves source maps, and maps Electron preload-to-main IPC communication channels.

REA Bridge Mechanism

100% built-in TypeScript/Rust engine. Directly projects compact summary views from 300MB+ Evidence files using rea inspect-analysis-view, avoiding disk and context window explosion.

Key Capabilities

Direct app.asar archive traversal without unpacking to disk
Preload script to main process IPC boundary mapping
SourceMap codec with accurate line-and-column attribution
Compact Evidence projection (reduces 300MB+ Evidence to 10KB)

CLI Usage Examples

Execute direct terminal analysis with --provider javascript:

rea asar-inspector example
npx -y rea-agents@latest analyze-javascript-application /path/to/app.asar --json
rea inspect-analysis-view app-view.json