English · 简体中文 · 日本語 · 한국어 · العربية
See a feature you like. Understand how it works, down to the binary level.
Quick start · How REA works · What you can analyze · Showcases · FAQ · Documentation
npx rea-agents setup
|
Join the Reverse Engineering Community Discord · Q&A · Show and Tell |
See a feature in an app that you want in your own product? Ask your agent to investigate it with REA. It can inspect the app without its source code, explain how the feature works, show the evidence, and build a version for your project.
REA connects your agent to tools for inspecting native binaries, JavaScript and Electron apps, .NET assemblies, and websites. You can also use the same tools from your terminal. Analysis runs locally, and results include the evidence and limitations behind each conclusion.
Setup registers REA with your agent and installs matching workflow instructions. Native analysis can use an existing Hopper or Ghidra installation; setup can optionally install Hopper with approval. Static JavaScript analysis needs neither engine.
Visit the REA website for setup instructions, illustrated guides, and real case studies.
With Node.js and npm installed, run:
npx rea-agents setupChoose your agents, review the proposed changes, and approve them. Setup adds REA's MCP server and matching workflow instructions, with backups of existing configuration. Restart your agent afterward.
Setup supports Claude Code, Codex, Cursor, Gemini CLI and other agents. See installation and setup for provider configuration and manual MCP registration.
Understand how search works in the Notes app, show me the evidence, and build a
similar feature for my project.
Replace Notes with your target app and the feature you want to understand.
Inspect an extracted JavaScript/Electron app directory or ASAR:
npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --jsonThe result includes modules, imports, Electron boundaries and their evidence.
Replace the path with your target, such as "D:/apps/example" on Windows.
To install the rea command for regular use:
npm install --global rea-agents
rea --helpFor native analysis, configure a provider first. See the CLI and Evidence guide for native commands, provider selection, snapshots and scripting.
REA changes quickly, and new releases include frequent bug fixes. Keep your installation up to date.
For an npm-installed CLI:
rea updateTo refresh your agent registrations and skill, run the setup command printed by the update.
If you use npx, update your agent setup with:
npx rea-agents@latest setupReview the setup changes and restart your agent. For one-off CLI commands,
use npx rea-agents@latest followed by the command.
Your agent calls REA through MCP to inspect the target and trace relevant code. REA returns findings with their evidence. The agent uses them to ask follow-up questions, explain the behavior, or write and test an implementation. CLI commands use the same workflows.
REA requires Node.js 22.x (>=22.19), 24.x (>=24.11), or 26+, plus npm. Additional tools and host support depend on the target:
| Target | What REA returns | Requirements and guide |
|---|---|---|
| Native binaries | Pseudocode, assembly, strings, symbols, calls and references | Hopper, Ghidra or IDA; native analysis |
| Offline ELF layout | Sections, segments, original symbols/relocations and static mitigation candidates | Caller-supplied pwntools on Linux x64; binary diagnostics |
| EVM bytecode | Dispatch selectors, byte offsets, inferred arguments and mutability | Local raw/hex carrier; offline EVM guide |
| Recorded Linux crashes | Raw notes, every recorded thread's registers/signals and optional mapping candidates | Caller-supplied pwntools; optional GDB/pwndbg; recorded crashes |
| JavaScript / Electron | Modules, imports, source maps, routes, IPC and native add-on relationships | Node.js and npm; application analysis |
| Websites | Page structure, scripts, network observations and requested screenshots | A Chrome-family browser; browser analysis |
| Saved network captures | Requests, responses, exposed payloads and source locations | HAR; mitmdump on Linux for native mitmproxy captures; capture guide |
| .NET assemblies | Metadata, CIL instructions, declared native dependencies and build comparisons | Static inspection; managed-code guide |
| Android APKs | Manifest declarations, classes, decompiled methods and references | Headless JADX and a full JDK on Linux/macOS; Android guide |
| Firmware | Regions, extraction results and native-analysis handoffs | Binwalk / Unblob on Linux; firmware guide |
| Packages and resources | File inventories, digests, plists, Apple bundle anatomy and extracted resources | Artifact and JavaScript guide, Apple applications |
| Process behavior | Terminal output, interactions, exit and filesystem observations, and run comparisons | Linux/macOS with a native PTY; process capture |
Static JavaScript and .NET inspection read the supplied files without running the application. Runtime capture runs or interacts with the selected target using your user permissions; each runtime guide describes its effects.
Native formats and host support vary by provider. See Hopper and Ghidra setup, the IDA guide, and experimental Windows Ghidra support. Ghidra also supports 16-bit DOS analysis. For provider selection, see the CLI guide. Check release availability for features added since the latest npm release.
Follow a sound call into its position-to-pan helper, inspect the instructions, and turn incomplete pseudocode into C. The reconstruction passes 3,205 original-x86 cases and reproduces all 63 compiled function bytes.
Read the case study · Reconstruction repository
Find the renderer's clipboard API, follow it through preload and IPC into the main process, and inspect the rich clipboard format.
Inspect the original PC-98 game's 16-bit instructions, recover the fixed and aimed angle calculations, and compare the reconstructed C++ with the historical compiler output.
Read the case study · Reconstruction repository
If you've used REA on something interesting, we'd love to see it. Share your case in an issue or a pull request, including the target, your question, how REA helped, and what you found.
Which agents can use REA?
Any agent that supports local MCP servers. Setup configures the supported agents; other clients can use manual MCP registration.
Do I need Hopper, Ghidra or IDA?
Deep native analysis uses one of them. Static JavaScript and .NET inspection work without a native analysis engine. Setup can install Hopper after approval; Ghidra and IDA use your existing installations. See provider setup.
Do I need to start Hopper first?
REA starts Hopper when an operation needs it. On macOS, a first-run dialog may ask you to choose demo mode or activate your license. See Hopper startup and troubleshooting.
What does installing the skill from skills.sh do?
The skill supplies investigation instructions for your agent. Use rea setup
to register REA's MCP server and install the matching instructions, then restart
your agent. See skill-only installation.
What code does REA return?
Native analysis returns pseudocode and assembly. JavaScript/Electron analysis recovers modules and their relationships. Your agent uses these findings to write and test an implementation; the showcases give worked examples.
Does REA upload my app?
REA analyzes targets locally. Your agent receives the tool results, and its model provider has its own data policy.
What should I do if I hit a bug?
Update first; a recent release may already fix it.
For an npm-installed CLI:
rea updateFor agent setup through npx:
npx rea-agents@latest setupIf you're using an agent, complete the setup refresh and restart it. Retry the same task. If the problem persists, open an issue with your REA version, target type, steps to reproduce and error output.
Start with the website's worked guides. For exact options, prerequisites and result contracts:
- Installation and setup: agent registration, provider configuration, updates and uninstall.
- Readiness and troubleshooting: diagnose one agent or analysis engine.
- CLI and Evidence: commands, provider selection, snapshots, import/export and exit statuses.
- MCP contracts and agent prompts: tool results, sessions and guided investigations.
- Tool catalog: build-generated inventory of tools, providers and CLI commands.
- Roadmap: planned work and capability trackers.
Report vulnerabilities through SECURITY.md.
We'd love your help with REA! Open an issue to report a bug or suggest a feature, or send a pull request to improve the code or docs.
See CONTRIBUTING.md for development setup and checks, testing for verification lanes, and the architecture map for the project structure.
Website · npm · skills.sh · Issues · Security
🎉 20,000 GitHub stars — thank you!
Thanks to everyone using REA, reporting bugs, testing builds, and contributing fixes.
REA provides tools for lawful reverse-engineering research, analysis, and reconstruction. You are responsible for obtaining any required authorization and complying with applicable laws. The project does not endorse illegal or unauthorized use.