REA gives Claude Code, Codex or Cursor the tools of reverse engineering. Here you understand the technology, see the real cases and find out whether it is worth it for you.

Reverse engineering is figuring out how a program works by looking only at the executable, without the source code. REA (Reverse Engineer Anything) is an open tool that connects your AI agent to decompilers such as Ghidra, from the NSA, and returns its conclusions with the proof and the limits of each one. It is for developers, security people and anyone who studies software. This guide gathers the links, explains everything in plain English, shows real cases and a test done here. To use it, you need Node.js and an AI agent in the terminal.
REA is not a new decompiler. It gives the agent simple commands on top of Ghidra, Hopper and IDA, which used to take weeks to master.
Opens native binaries (Mac, Windows, Linux), Electron/JavaScript apps, .NET, Android and websites, and shows how a function works.
Every answer comes in four parts: evidence, recovered map, limits and what was left unanswered. No "trust me" paragraph.
The analysis runs locally. The analyzed program is not uploaded; only the results go to your agent's model.
Compiling erases names, types and comments. Reverse engineering is the way back, and REA puts the agent to work on that path.




For JavaScript/Electron apps, Node is enough. For native binaries, you need an installed decompiler.
Versions 22.19+, 24.11+ or 26+ (23 and 25 are not supported).
node -vClaude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf, OpenCode, Copilot CLI, VS Code and others.
claude --versionGhidra (free, needs Java), Hopper or IDA. The setup can install Hopper, with your permission.
# Ghidra: download at github.com/NationalSecurityAgency/ghidra/releases
Commands from the project itself. REA changes almost every day: check the version first.
Static analysis of an Electron app needs neither Ghidra nor MCP, and does not run the app. Point it at the folder or the app.asar.
npx -y rea-agents@latest analyze-javascript-application /caminho/absoluto/app.asar --json
The setup shows the plan, backs up your configuration and asks before changing anything. It registers the MCP server and installs the investigation method (skill).
npx rea-agents setup # restart the agent afterwards
The scoped doctor tests one agent or one specific engine, without failing on something you will not even use.
rea doctor --client claude_code --json rea doctor --provider ghidra --json
In plain language, with a program of yours or one you are authorized to analyze.
"Understand how search works in app X, show me the evidence
and build something similar in my project."
Numbers taken from the repositories and the official site on Oct 10, 2026.

FUN_… functions). The agent found the right function, recovered the 3 rules from the code and wrote a generator: AGNT-1001 opened it.


Assessment based on the documentation, the published cases and a test on this machine.
• Developers who want to understand how a very good app handles search, sync or the clipboard.
• Security and privacy: audit the apps on your machine and see what they send out.
• Recovering logic from a program of yours whose code was lost.
• Study, CTF and preservation of old software.
• People who build tools for AI: the evidence · map · limits · unknowns format is a great model.
• People who do not use a terminal: it requires Node and patience with versions that change every day (5.0 → 6.3 in three days).
• Copying a competitor's product: legally risky and misses the point.
• Heavily protected programs (VMProtect, heavy obfuscation) or with the logic on the server.
• Expecting miracles from any model: on deliberately protected binaries, even the best models solve only part of the cases (SRE-Bench).
We ran REA 6.3.0 (analyze-javascript-application, no Ghidra, no MCP) on a Linux ARM server. It worked on one of our own Node apps (97 files, 3.5 MB): in 20 s and 1.3 GB of RAM it returned a graph with 2,109 nodes and 3,104 edges, 2,508 findings and 5 declared limitations, without running the app. It hung on two targets that had a single huge JS file (the bundle of an installed Electron app and typescript/_tsc.js, 6 MB): it sat at 100% CPU for more than 20 min on the same file, ignored SIGTERM and only stopped with kill -9. Bottom line: it works well on normal-sized projects; on large apps, run it with a time cap (timeout -s KILL) and without node_modules. The full JSON is huge (241 MB here): day to day, let the agent query it through MCP instead of reading the whole file.
For those who sell software: assume any agent can map your app. What protects you is data, the server, distribution, trust and speed, not closed code.
Third-party projects. Stars and versions checked on Oct 10, 2026.
REA: MCP + reverse engineering CLI for agents. TypeScript, MIT, ~61k stars, version 6.3.0.
Official site with illustrated guides (native, JavaScript, browser) and the case studies.
Free, open-source decompiler from the NSA. Java, Apache-2.0, ~82k stars, version 12.1.4.
DX-Ball 1.07 rebuilt in C/C++ with REA + Ghidra, tested byte for byte. MIT. The game files are not included.
Reconstruction of a PC-98 game (DOS, 16-bit): the bullet ring calculation. MIT.
Photoshop rebuilt from scratch in Rust (clean room), ~39k stars, alpha. Also FilmCraft (Premiere) and LightCraft (Lightroom), from the ArtCraft suite.
Columbia University benchmark: agents reverse engineering protected binaries. Under development.
README in PT/EN/ES with the links and the assessment.
REA itself warns you: the responsibility is yours.

rea update or npx rea-agents@latest setup before reporting a problem.