REA Gives AI Coding Agents Reverse-Engineering Tools
A new open-source Model Context Protocol server named REA allows AI coding agents to reverse engineer software, inspect application binaries, and recreate features across different tech stacks.

Developers can now equip AI coding agents with full reverse-engineering capabilities using REA, short for Reverse Engineer Anything. Released as an MIT-licensed open-source project hosted at github.com/morluto/rea with documentation at morluto.github.io/rea, the toolkit operates as a local Model Context Protocol server. The repository currently holds 90 GitHub stars and delivers tools through the npm package rea-agents.
Running npx rea-agents setup automatically registers the MCP server with supported client applications and installs a matching workflow skill. The platform supports a wide range of developer assistants, including Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf, Devin, OpenCode, Antigravity, GitHub Copilot CLI, Command Code, and VS Code, while allowing other clients to connect through manual local MCP configurations.
For deep native binary analysis, REA routes requests directly to disassemblers such as Hopper, Ghidra, or IDA Pro. All disassemblers operate on a bring-your-own-license basis, as REA does not bundle Ghidra, Java, or IDA. However, REA can automatically install Hopper during setup on macOS and Linux or record an existing Ghidra path. For static JavaScript and Electron analysis, only Node.js is required.
Target formats supported by the framework include Mach-O, ELF, PE, Electron, .NET, Android APK files, hardware firmware, static JavaScript, and passive browser inspection via a running Chrome instance with CDP access.
For engineering teams, REA reorganizes complex analysis into a three-stage workflow centered on decompiling, understanding, and recreating software. Coding agents can inspect applications without source code access, trace specific features, cite supporting evidence, and output compatible implementations for new stacks. Every result includes confidence metrics, supporting evidence, and explicit limitations rather than claiming complete source recovery.
This is our own summary of reporting by AlphaSignal



