REA (Reverse Engineer Anything) is a free, MIT-licensed MCP server and CLI that lets Claude Code, Codex, Cursor and nine other agents take apart an app you do not have the source for, from Electron bundles down to native binaries, and explain how a feature works with evidence attached. It gained 2,956 GitHub stars in a single day this week and sits at roughly 9,500 total, a day after version 4.1.0 shipped on October 6, 2026.

  • One command, npx rea-agents setup, registers REA with your agents and shows every config change before it writes anything.
  • JavaScript and Electron apps need nothing but Node.js; native binaries need Hopper, Ghidra 12.1.4 or IDA Pro behind it.
  • On Windows the CLI and static JavaScript analysis run fine (we tested both), but native analysis is limited to an experimental, read-only Ghidra mode.
  • Every answer comes back as an Evidence record with file locations, confidence and a list of what REA could not prove.

The exact steps, start to finish

  1. Check your runtime. REA supports Node.js 22.x (22.19 or newer), 24.x (24.11 or newer) and 26+. Node 23 and 25 are not supported.
    $ node --version
    $ npm --version
  2. Run guided setup. Pick which agents get REA, read the plan, then approve it.
    $ npx rea-agents setup
  3. Connect a native analysis engine (skip this if you only care about JavaScript and Electron apps). On macOS and Linux, setup offers to install Hopper, whose demo mode works for analysis. On Windows, download Ghidra 12.1.4 and a 64-bit JDK 21 (for example from Adoptium), then point REA at them.
    # PowerShell
    $env:GHIDRA_INSTALL_DIR = "C:\tools\ghidra_12.1.4_PUBLIC"
    $env:JAVA_HOME = "C:\Program Files\Java\jdk-21"
    rea doctor --json
    rea providers --json
    
    # cmd.exe
    set GHIDRA_INSTALL_DIR=C:\tools\ghidra_12.1.4_PUBLIC
    set JAVA_HOME=C:\Program Files\Java\jdk-21
    rea doctor --json
    rea providers --json
  4. Check readiness. Doctor changes nothing; it reports what is missing and how to fix it.
    $ npx -y rea-agents@latest doctor
  5. Get a first result from the terminal. Point it at an extracted Electron app folder or an .asar file. No engine needed, and the app is never executed.
    $ npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --json
  6. Restart your agent and ask it a real question. For example:
    Understand how search works in the Notes app, show me the evidence, and build a
    similar feature for my project.
How REA routes an agent's question to analysis engines An agent or terminal sends a request to REA's CLI and MCP server, which routes it to Hopper, Ghidra, IDA, a static JavaScript analyzer or a browser observer, and returns an Evidence record. REA · ONE MCP, MANY ENGINES Your agent Terminal (rea) REA CLI + MCP server Hopper Ghidra 12.1.4 IDA Pro (via MCP) JS / Electron static Browser (CDP) Evidence + limitations Orange = needs only Node.js. Grey engines are separate installs. genztech.blog
Fig 1 REA sits between the agent and whichever analysis engine fits the target. Only the static JavaScript path works with nothing but Node installed.

What REA found inside a 20-line Electron app

Before trusting it with anything real, we wrote a tiny Electron "notes" app on a Windows 10 laptop: a main process with two ipcMain.handle channels, a preload script exposing them through contextBridge, and a store module that writes JSON to disk. Then we pointed REA 4.1.0 at the folder with Node 24.17.

RelatedOrca Setup: Run a Fleet of Coding Agents in Parallel

The first npx call took about a minute, almost all of it npm downloading the package. After that, analyze-javascript-application returned a graph of 27 nodes. It named both IPC channels, notes:search and notes:save, paired each renderer call with its main-process handler, found the one window, the one preload entry point and the two members exposed to the page, and pointed to exact line and column ranges in src/preload.js. It parsed three JavaScript files and never ran any of them.

The part we liked most was the honesty. The result carried six limitations, including a note that the Electron relationships came from inert syntax, so runtime registration and reachability "remain unproven." That is exactly what you want an agent to read before it tells you how a competitor's app works. The default output is long, though: nearly 19,200 lines for our toy app, and --token-count put it at 150,711 tokens, a big slice of any agent's context window. The CLI's global --filter-output option fixes that. This prints only the IPC summary:

$ npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --filter-output normalized_result.summary.ipc

Running REA on Windows, macOS and Linux

The README lists macOS 12+, Ubuntu 24.04+, Fedora 41+ and 64-bit Arch as the supported hosts, and Windows support is newer and narrower. Here is how it splits:

  • macOS: the full experience. Setup can install Hopper into ~/Applications after you approve it, without Homebrew or admin rights, and REA adds Mach-O, plist, code-signature and Swift demangling tools that do not even need Hopper.
  • Linux: setup can install Hopper plus its demo-session dependencies (Xvfb, Python 3, X11, XTEST) through your package manager. The usual launcher path is /opt/hopper/bin/Hopper.
  • Windows: the CLI, setup, doctor and static JavaScript work. Hopper installation is unavailable, and native analysis means Ghidra's experimental "P0" mode: read-only, native x86-64 PE files only, on a local NTFS drive. Process capture and historical source import are not available natively; the docs say to run Linux REA inside WSL for those.

If you would rather have a global rea command than type npx every time, the docs give two routes:

# any OS with Node and npm
npm install --global rea-agents
rea setup

# macOS / Linux installer script
curl -fsSL https://raw.githubusercontent.com/morluto/rea/main/install.sh | bash

Update either one later with rea update.

Wiring REA into an agent that setup does not list

Setup knows Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf, Devin, OpenCode, Antigravity, GitHub Copilot CLI, Command Code and VS Code. Anything else that can launch a local MCP server can use the manual config from the README, pinned to an exact version:

RelatedPI-Desktop Setup: Run Any AI Coding Agent Locally, Free

{
  "mcpServers": {
    "rea": {
      "command": "npx",
      "args": ["-y", "rea-agents@4.1.0", "mcp"]
    }
  }
}

The pin matters. The project's own docs recommend one exact version per registration, and rea setup keeps that pin in sync with the bundled skill. If you only want the investigation workflow as a skill, there is also npx skills add morluto/rea --skill reverse-engineer-anything, though setup already installs a matching copy.

To back out cleanly, rea uninstall removes only REA's own MCP registrations and skill, and rea uninstall --purge-data also clears ~/.rea/cache and ~/.rea/state. Hopper, Node and your evidence files stay put.

Fixing "missing_analysis_engine" and other first-run errors

Doctor is the first stop for almost everything. On our fresh Windows machine it flagged Hopper, Ghidra and the IDA registration as missing_analysis_engine, and the REA skill as config_drift. None of that blocks JavaScript analysis; the docs say unavailable optional providers stay informational.

  • Hopper exists but doctor cannot find it: set the path explicitly with export HOPPER_LAUNCHER_PATH=/absolute/path/to/Hopper, then run rea doctor --json. On Linux, ldd /opt/hopper/bin/Hopper | grep 'not found' lists missing shared libraries.
  • Ghidra not detected: it has to be exactly Ghidra 12.1.4 with a 64-bit full JDK 21, including javac. REA never downloads or changes either one.
  • Setup exits with status 1: that is needs_confirmation or needs_human, not a crash. Rerun it and approve the plan. setup --dry-run prints the plan without touching anything.
  • The first Ghidra query times out in your agent: the first query triggers import and auto-analysis, which can outlast a client's default deadline. Ask again; analysis_activity reports whether the engine is still busy.

REA next to Ghidra, IDA and Hopper on their own

REA is not a disassembler. It is the layer that lets an agent drive one, plus its own JavaScript, .NET, Android and browser analyzers.

REAGhidra aloneIDA Pro + ida-pro-mcpHopper alone
What it isAgent layer + CLI over several enginesFree NSA disassembler and decompilerCommercial disassembler with a community MCP bridgeCommercial macOS/Linux disassembler with a demo
Agent accessBuilt in, 12 agents in setupNeeds a separate bridgeYes, through the bridgeNo, unless driven by REA
Electron / JS appsStatic graph of IPC, preload, modulesNoNoNo
WindowsCLI and JS yes; native is read-only Ghidra P0YesYesNo
OutputEvidence records with limitationsGUI projectGUI databaseGUI document

Who should install it today? If you work on Electron apps, or you have ever wondered how a desktop app built on web tech wires its renderer to its main process, REA is worth five minutes right now, on any OS, with no engine at all. Mac users with Hopper get the most complete version. Windows users who live in IDA or Ghidra already have strong tools, and REA mostly adds the agent hookup and the evidence trail. Whatever you point it at, read the software's license first: some EULAs restrict reverse engineering, and REA does not change what you are allowed to do.

Primary sources