REA (Reverse Engineer Anything)

Wires coding agents into Hopper, Ghidra and web tooling so developers can dissect shipped apps

Reverse engineer anything with agents, from app behavior down to native binaries.

No video published yet. The write-up below covers what the tool does and how to try it.

Category
Developer tools
Audience
Developers
Language
TypeScript
Licence
MIT

Published Updated

REA, short for Reverse Engineer Anything, is a TypeScript toolkit that hands an AI coding agent a set of reverse-engineering tools so it can pull apart a compiled program and explain how one of its features works. It is for developers who spot something in a shipped product — a native desktop binary, a JavaScript or Electron app, a website — and want a traced answer about how it was built instead of a guess. The project is MIT-licensed, installs from npm as rea-agents, and carries 6,855 stars and 756 forks on GitHub, with the first commits dated April 2026 and pushes continuing through October 2026.

What it does

The use case the authors lead with is simple: you see a feature you like, there is no source code, and you want to understand it well enough to build your own version. With REA connected, you ask your agent to explain how that feature works. According to the project, the agent then decompiles the target, traces the relevant code, and shows the evidence behind its explanation rather than summarising from the outside. The last step is the one the channel's video emphasises: once the agent has an account of how the original works, you can ask it to turn that understanding into a feature in your own codebase.

The stated target range is broad — native binaries at the bottom, JavaScript applications in the middle, plain websites at the top. The GitHub topics also point at disassembler, decompiler, static-analysis and CTF work, so capture-the-flag players are clearly part of the intended audience alongside app developers.

How it works

REA is built as an MCP server — Model Context Protocol is how it exposes its capabilities, and the README advertises a "tool catalog for investigation" that an agent can call into. Instead of one magic command, the agent picks tools: inspect, disassemble, decompile, follow a symbol, and so on, under what the README calls an investigation model.

For native code it does not implement its own disassembler. It bridges into one you already have: the README's screenshot shows REA launching an analysis bridge inside Hopper while inspecting a native binary, and Ghidra is named as the other supported backend. The topic list also mentions agent skills and a dsh plugin, but the saved README excerpt stops before those are explained, so treat the details as unverified until you read the current repository.

Getting started

The repository is at github.com/morluto/rea and setup is a single command, npx rea-agents setup, which means Node.js is a hard requirement — the README's badge asks for version 22.19 or newer. Beyond that, the project does not list an operating system, chip or memory requirement, so do not assume any particular platform; the Hopper-based workflow in the screenshot is the one the authors show.

Costs break down in two places. REA itself is free and MIT-licensed, with no service of its own to pay for. The intelligence is not included: REA connects to your coding agent, so you pay whatever that agent costs — a paid API key for a cloud model, or your own hardware if you run a local one. Decompilation is also not included. For native binaries you must install Hopper or Ghidra yourself and bring whatever licence each of those requires; REA drives them, it does not ship them.

There is a Discord server linked from the README if you get stuck during setup.

When to use it / when not

The main catch is the one the video states outright: native binaries still need Hopper or Ghidra installed. On a fresh machine with neither, the native half of the promise does not work, and the JavaScript and website paths are the parts you can try immediately.

Use it instead of just asking Claude or ChatGPT how a feature probably works when you need the answer tied to the actual shipped artefact — the pitch here is evidence from the binary, not plausible reconstruction from training data. Use it instead of driving IDA or Ghidra by hand when the question is narrow and you would rather describe it in English than learn a disassembler's workflow.

Do not use it if you expect a push-button decompiler: this is an agent harness, and the quality of the result depends on the model you attach and on your own ability to judge what it reports. Do not treat it as settled software either — the README keeps "Current status" and "Roadmap" sections, and the repository is only a few months old. Nothing in the material covers the legal side of reverse-engineering someone else's product, so that homework is yours.

Take REA seriously if you already do this work and want the tedious parts delegated: security researchers, CTF players, and developers who regularly reason about closed-source behaviour on their own platform. It is an orchestration layer over the disassemblers and browser tooling you already own, and it is honest about that boundary. If you have never opened a decompiler and do not intend to install one, the native promise in the title will stay out of reach, and the JavaScript and web paths are what you are actually buying into.

More in Developer tools

All of Developer tools →