REA (Reverse Engineer Anything) is a free, MIT-licensed MCP server and CLI that lets Claude Code, Codex, Cursor and nine other agents take apart an app you do not have the source for, from Electron bundles down to native binaries, and explain how a feature works with evidence attached. It gained 2,956 GitHub stars in a single day this week and sits at roughly 9,500 total, a day after version 4.1.0 shipped on October 6, 2026.
- One command,
npx rea-agents setup, registers REA with your agents and shows every config change before it writes anything. - JavaScript and Electron apps need nothing but Node.js; native binaries need Hopper, Ghidra 12.1.4 or IDA Pro behind it.
- On Windows the CLI and static JavaScript analysis run fine (we tested both), but native analysis is limited to an experimental, read-only Ghidra mode.
- Every answer comes back as an Evidence record with file locations, confidence and a list of what REA could not prove.
The exact steps, start to finish
- Check your runtime. REA supports Node.js 22.x (22.19 or newer), 24.x (24.11 or newer) and 26+. Node 23 and 25 are not supported.
$ node --version $ npm --version - Run guided setup. Pick which agents get REA, read the plan, then approve it.
$ npx rea-agents setup - Connect a native analysis engine (skip this if you only care about JavaScript and Electron apps). On macOS and Linux, setup offers to install Hopper, whose demo mode works for analysis. On Windows, download Ghidra 12.1.4 and a 64-bit JDK 21 (for example from Adoptium), then point REA at them.
# PowerShell $env:GHIDRA_INSTALL_DIR = "C:\tools\ghidra_12.1.4_PUBLIC" $env:JAVA_HOME = "C:\Program Files\Java\jdk-21" rea doctor --json rea providers --json # cmd.exe set GHIDRA_INSTALL_DIR=C:\tools\ghidra_12.1.4_PUBLIC set JAVA_HOME=C:\Program Files\Java\jdk-21 rea doctor --json rea providers --json - Check readiness. Doctor changes nothing; it reports what is missing and how to fix it.
$ npx -y rea-agents@latest doctor - Get a first result from the terminal. Point it at an extracted Electron app folder or an
.asarfile. No engine needed, and the app is never executed.$ npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --json - Restart your agent and ask it a real question. For example:
Understand how search works in the Notes app, show me the evidence, and build a similar feature for my project.
What REA found inside a 20-line Electron app
Before trusting it with anything real, we wrote a tiny Electron "notes" app on a Windows 10 laptop: a main process with two ipcMain.handle channels, a preload script exposing them through contextBridge, and a store module that writes JSON to disk. Then we pointed REA 4.1.0 at the folder with Node 24.17.
RelatedOrca Setup: Run a Fleet of Coding Agents in Parallel
The first npx call took about a minute, almost all of it npm downloading the package. After that, analyze-javascript-application returned a graph of 27 nodes. It named both IPC channels, notes:search and notes:save, paired each renderer call with its main-process handler, found the one window, the one preload entry point and the two members exposed to the page, and pointed to exact line and column ranges in src/preload.js. It parsed three JavaScript files and never ran any of them.
The part we liked most was the honesty. The result carried six limitations, including a note that the Electron relationships came from inert syntax, so runtime registration and reachability "remain unproven." That is exactly what you want an agent to read before it tells you how a competitor's app works. The default output is long, though: nearly 19,200 lines for our toy app, and --token-count put it at 150,711 tokens, a big slice of any agent's context window. The CLI's global --filter-output option fixes that. This prints only the IPC summary:
$ npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --filter-output normalized_result.summary.ipc
Running REA on Windows, macOS and Linux
The README lists macOS 12+, Ubuntu 24.04+, Fedora 41+ and 64-bit Arch as the supported hosts, and Windows support is newer and narrower. Here is how it splits:
- macOS: the full experience. Setup can install Hopper into
~/Applicationsafter you approve it, without Homebrew or admin rights, and REA adds Mach-O, plist, code-signature and Swift demangling tools that do not even need Hopper. - Linux: setup can install Hopper plus its demo-session dependencies (Xvfb, Python 3, X11, XTEST) through your package manager. The usual launcher path is
/opt/hopper/bin/Hopper. - Windows: the CLI, setup, doctor and static JavaScript work. Hopper installation is unavailable, and native analysis means Ghidra's experimental "P0" mode: read-only, native x86-64 PE files only, on a local NTFS drive. Process capture and historical source import are not available natively; the docs say to run Linux REA inside WSL for those.
If you would rather have a global rea command than type npx every time, the docs give two routes:
# any OS with Node and npm
npm install --global rea-agents
rea setup
# macOS / Linux installer script
curl -fsSL https://raw.githubusercontent.com/morluto/rea/main/install.sh | bash
Update either one later with rea update.
Wiring REA into an agent that setup does not list
Setup knows Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf, Devin, OpenCode, Antigravity, GitHub Copilot CLI, Command Code and VS Code. Anything else that can launch a local MCP server can use the manual config from the README, pinned to an exact version:
RelatedPI-Desktop Setup: Run Any AI Coding Agent Locally, Free
{
"mcpServers": {
"rea": {
"command": "npx",
"args": ["-y", "rea-agents@4.1.0", "mcp"]
}
}
}
The pin matters. The project's own docs recommend one exact version per registration, and rea setup keeps that pin in sync with the bundled skill. If you only want the investigation workflow as a skill, there is also npx skills add morluto/rea --skill reverse-engineer-anything, though setup already installs a matching copy.
To back out cleanly, rea uninstall removes only REA's own MCP registrations and skill, and rea uninstall --purge-data also clears ~/.rea/cache and ~/.rea/state. Hopper, Node and your evidence files stay put.
Fixing "missing_analysis_engine" and other first-run errors
Doctor is the first stop for almost everything. On our fresh Windows machine it flagged Hopper, Ghidra and the IDA registration as missing_analysis_engine, and the REA skill as config_drift. None of that blocks JavaScript analysis; the docs say unavailable optional providers stay informational.
- Hopper exists but doctor cannot find it: set the path explicitly with
export HOPPER_LAUNCHER_PATH=/absolute/path/to/Hopper, then runrea doctor --json. On Linux,ldd /opt/hopper/bin/Hopper | grep 'not found'lists missing shared libraries. - Ghidra not detected: it has to be exactly Ghidra 12.1.4 with a 64-bit full JDK 21, including
javac. REA never downloads or changes either one. - Setup exits with status 1: that is
needs_confirmationorneeds_human, not a crash. Rerun it and approve the plan.setup --dry-runprints the plan without touching anything. - The first Ghidra query times out in your agent: the first query triggers import and auto-analysis, which can outlast a client's default deadline. Ask again;
analysis_activityreports whether the engine is still busy.
REA next to Ghidra, IDA and Hopper on their own
REA is not a disassembler. It is the layer that lets an agent drive one, plus its own JavaScript, .NET, Android and browser analyzers.
| REA | Ghidra alone | IDA Pro + ida-pro-mcp | Hopper alone | |
|---|---|---|---|---|
| What it is | Agent layer + CLI over several engines | Free NSA disassembler and decompiler | Commercial disassembler with a community MCP bridge | Commercial macOS/Linux disassembler with a demo |
| Agent access | Built in, 12 agents in setup | Needs a separate bridge | Yes, through the bridge | No, unless driven by REA |
| Electron / JS apps | Static graph of IPC, preload, modules | No | No | No |
| Windows | CLI and JS yes; native is read-only Ghidra P0 | Yes | Yes | No |
| Output | Evidence records with limitations | GUI project | GUI database | GUI document |
Who should install it today? If you work on Electron apps, or you have ever wondered how a desktop app built on web tech wires its renderer to its main process, REA is worth five minutes right now, on any OS, with no engine at all. Mac users with Hopper get the most complete version. Windows users who live in IDA or Ghidra already have strong tools, and REA mostly adds the agent hookup and the evidence trail. Whatever you point it at, read the software's license first: some EULAs restrict reverse engineering, and REA does not change what you are allowed to do.
- Repomorluto/rea on GitHub README, requirements, CLI and MCP config
- Releaserea-agents 4.1.0 release notes published October 6, 2026
- DocsInstallation and setup guide Node versions, Windows Ghidra, Hopper
- Packagerea-agents on npm
- DependencyGhidra releases 12.1.4 is the version REA requires
