# REA (Reverse Engineer Anything)

> Source: https://aiwiki.ai/wiki/rea_reverse_engineer_anything
> Updated: 2026-10-10
> Fact-checked: 2026-10-10
> Categories: AI Agents, Developer Tools, Open Source AI, Software Development
> License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/) - attribute to "AI Wiki (aiwiki.ai)"
> Cite as: AI Wiki. "REA (Reverse Engineer Anything)." aiwiki.ai, 10 Oct 2026. https://aiwiki.ai/wiki/rea_reverse_engineer_anything
> From AI Wiki (https://aiwiki.ai), the free encyclopedia of artificial intelligence. Reuse freely with attribution.

REA (Reverse Engineer Anything) is a software-analysis toolkit in the `morluto/rea` repository. It exposes local inspection tools through the [Model Context Protocol](https://aiwiki.ai/wiki/model_context_protocol) and a command-line interface. Coding agents use its findings to investigate application behavior and develop their own implementations.[1]

## Analysis targets

REA's documented targets include the following.[1]

| Target | Documented inspection | Requirements |
|---|---|---|
| Native binaries | Assembly, pseudocode, symbols, and cross-references | Hopper, Ghidra, or IDA.[1] |
| JavaScript and Electron applications | Modules, imports, source maps, and interprocess communication | Node.js and npm.[1] |
| .NET assemblies | Metadata and CIL instructions | Static inspection without a native-analysis engine.[1] |
| Websites | Page structure, scripts, and network observations | A Chrome-family browser.[1] |
| Android APKs | Manifest declarations, classes, and decompiled methods | Headless JADX and a full JDK on supported hosts.[1] |

Static JavaScript and .NET inspection read supplied files without running the application.[1]

The project's Electron guide follows an export operation through a renderer API, a preload bridge, an IPC channel, and a main-process file writer. Static analysis pairs literal channel names with handlers and records source locations. Computed names or ambiguous handlers can remain unresolved; code-derived paths are inferences until runtime observations establish what executed.[7]

## Setup and version boundaries

The npm package is `rea-agents`. REA supports Node.js 22.x from 22.19, 24.x from 24.11, and 26 or later; its installation guide excludes Node.js 23, 25, and prereleases.[2]

```sh
npx rea-agents@latest setup
```

Setup can configure clients including [Claude Code](https://aiwiki.ai/wiki/claude_code), [OpenAI Codex](https://aiwiki.ai/wiki/openai_codex), [Cursor](https://aiwiki.ai/wiki/cursor), and [Gemini CLI](https://aiwiki.ai/wiki/gemini_cli). It presents a plan for approval, preserves unrelated configuration, and backs up changed files. Permission to download the npm package does not approve those configuration changes or an optional Hopper installation.[2]

Installing REA's [agent skill](https://aiwiki.ai/wiki/agent_skills) alone supplies instructions, not an MCP registration or analysis engines. Registrations pin the version used during setup. Repository `main` can describe later functionality than the published package, so the running server's schemas and available tools determine usable features.[2]

## CLI and evidence

These illustrative commands inspect a supplied native program through Ghidra; they require that provider to be configured.[3]

```sh
rea analyze /absolute/path/to/program --provider ghidra --json
rea decompile /absolute/path/to/program 0x1000 --provider ghidra --json
rea xrefs /absolute/path/to/program 0x1000 --provider ghidra --json
```

`analyze` returns an overview, `decompile` returns pseudocode, and cross-reference queries locate relationships. Each CLI invocation is a separate process. Saved Evidence records retain artifact identity, source locations, observations, inferences, and unresolved findings; import, export, and comparison commands operate on these records.[3]

Analysis snapshots reuse eligible exact results when target bytes, operation, parameters, provider, and settings match. They are not saved provider databases. New queries may still need the analysis engine, and mutation or cursor-dependent calls are excluded from caching.[3]

For MCP clients, `binary_session` reports tool availability and reasons for unavailable operations. Opening a target establishes a provider binding; REA does not silently substitute another provider after its failure. Cancellation and timeout are separate outcomes, and a rejected client request does not itself prove server work has stopped.[4]

MCP clients control their confirmation interfaces. REA does not require a permission grant on every tool call, and its effect annotations are descriptions rather than authorization controls.[4]

## Runtime capture and data handling

Process capture launches a caller-selected command and records bounded terminal, interaction, exit, and selected filesystem observations. It runs with the user's permissions and inherited environment. It is not a sandbox: selecting observation paths does not limit what the launched process can access.[5]

New process captures require Linux or macOS with the supported native PTY backend. Filesystem snapshots can miss short-lived changes; incomplete observations and truncation remain explicit in the result rather than proving two executions equivalent.[5]

The project states that target analysis happens locally, but tool results reach the coding agent and remain subject to its model provider's data policy.[1]

## Licensing and use

REA uses the MIT License, which permits modification and distribution subject to retaining its copyright and permission notice. The license disclaims warranties.[6]

The project describes its intended use as lawful reverse-engineering research and makes users responsible for required authorization. Analysis findings and a coding agent's subsequent implementation are distinct outputs.[1]

## References

1. morluto. [REA: Reverse Engineer Anything](https://github.com/morluto/rea), repository README, accessed 10 October 2026.
2. REA. [Installation and setup](https://github.com/morluto/rea/blob/main/docs/installation.md), accessed 10 October 2026.
3. REA. [CLI and Evidence](https://github.com/morluto/rea/blob/main/docs/cli.md), accessed 10 October 2026.
4. REA. [MCP runtime contracts](https://github.com/morluto/rea/blob/main/docs/mcp-contracts.md), accessed 10 October 2026.
5. REA. [Process capture](https://github.com/morluto/rea/blob/main/docs/process-capture.md), accessed 10 October 2026.
6. morluto. [MIT License](https://github.com/morluto/rea/blob/main/LICENSE), copyright 2026.
7. REA. [JavaScript and Electron Analysis](https://rea.tools/guides/javascript/), accessed 10 October 2026.
