Reverse engineer anything with agents, from app behavior down to native binaries.
$ npx -y skills add morluto/rea --agent claude-code
Repo: morluto/rea
What's inside
English · 简体中文 · 日本語 · 한국어 · العربية
See a feature you like. Understand how it works, down to the binary level.
Quick start · Current status · Investigation model · Tool catalog · Roadmap · How it works
npx rea-agents setup
See a feature in an app that you want in your own product? Ask your agent to investigate it with REA. It can inspect the app without its source code, explain how the feature works, show the evidence, and build a version for your project.
REA connects your agent to tools for inspecting native binaries, JavaScript and Electron apps, .NET assemblies, and websites. You can also use the same tools from your terminal. Analysis runs locally, and results include the evidence and limitations behind each conclusion.
Setup registers REA with your agent and installs matching workflow instructions. Native analysis can use an existing Hopper or Ghidra installation; setup can optionally install Hopper with approval. Static JavaScript analysis needs neither engine.
Set up REA with your agent:
npx rea-agents setup
Choose which supported agents should use REA, then review the exact paths and changes before approving. Existing REA registrations are selected by default; newly detected agents are available to select, but detection alone does not select them. Setup adds MCP access and REA's guided workflow for selected agents. Hopper is a separate optional choice with its own consent. Setup can also record an existing Ghidra installation.
Setup shows its changes before applying them and backs up existing configuration. See Installation and setup for requirements and setup options.
Add the skill to your AI coding assistant for richer context:
npx skills add morluto/rea --skill reverse-engineer-anything
The skill provides REA's investigation workflow. Run setup above to connect REA to your agent and configure analysis tools. Setup already installs a version-matched skill by default; this command installs the repository version.
After setup, restart your agent and describe the app or feature you want to understand. Hopper can run in demo mode; if it shows a first-run prompt, choose the demo or enter an existing license.
REA supports Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf, Devin, OpenCode, Antigravity, GitHub Copilot CLI, Command Code, and VS Code. Existing REA registrations are selected by default during setup; other detected agents remain unselected until chosen. Other agents can use the manual MCP configuration.
For your extracted JavaScript/Electron application tree or ASAR, run:
npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --json
Replace the path with your target (for example, "D:/apps/example" on Windows).
This returns inline Evidence, recovered graph, limitations, and unknowns without
MCP setup, Hopper, Ghidra, or executing the application. For a native app, configure
its engine first, then use analyze with that app's path. Run doctor when you
need diagnosis; it is not a prerequisite for each analysis.
rea doctor without options is an audit of the whole integration. It checks
every detected agent registration, the installed skill, and every optional
analysis engine, so it can report healthy: false while your current task works.
Choose a readiness scope for the work you are doing:
| Task | Readiness check |
|---|---|
| Static JavaScript/Electron analysis | None. Run analyze-javascript-application directly. |
| Troubleshoot one analysis engine | rea doctor --provider ghidra --json (or hopper, ida) |
| Check one agent's MCP registration | rea doctor --client codex --json (see client IDs) |
| Check the installed skill | rea doctor --skill --json |
A scoped report has scope.mode: "explicit". Only scope_checks determine
healthy and the exit status. Everything else is listed in
informational_checks; you don't need to fix it for this task. For example, a
missing engine you are not using needs no repair. environment_healthy still
summarizes the full audit. --target adds a target check, but without a scope
option the report remains audit-wide.
When more than one installed engine supports a native target, REA does not pick
one: opening the target fails with code: "capability_unavailable",
details.selection_reason: "ambiguous", and the providers in
details.candidate_ids. Choose one once: pass --provider on
the CLI or provider_id on open_binary, or set REA_ANALYSIS_PROVIDER as a
standing preference. An explicit selector overrides the environment variable.
The session keeps that choice and never falls back to another engine.
Recovery depends on details.selection_reason. For ambiguous, choose one of
the candidates. For provider_unavailable, the engine you selected needs repair,
so run rea doctor --provider <id> --json and follow its remediation. Neither
reason means you have to install every engine. See
Choosing a deep-analysis provider.
Install the command-line interface:
curl -fsSL https://raw.githubusercontent.com/morluto/rea/main/install.sh | bash
The installer adds rea to your system and starts setup when run in a terminal. It requires Node.js and npm to be installed already.
Alternatively, install with npm, then run setup:
npm install --global rea-agents
rea setup
Update either installation with rea update.
Static JavaScript inspection requires the Node/npm runtime only. Host and external-tool prerequisites depend on the selected workflow; the native provider guides describe their supported platforms.
Deep native binary analysis requires Hopper, Ghidra, or IDA Pro. Hopper is separate software with its own license; its demo supports analysis with vendor-defined limits. Ghidra and IDA are bring-your-own providers.
Firmware region inspection and explicit extraction use caller-supplied Binwalk and Unblob on Linux. See Firmware analysis for setup, provenance, resource limits and native handoff.
Static APK analysis uses a separately supplied headless JADX JAR and a full JDK, with no emulator or APK execution. See Android analysis for setup, CLI/MCP operations, coverage and public test fixtures. Authenticated IPA and macOS .app, ZIP, or DMG inventory Evidence can be projected into bundle anatomy, such as XPC services, app extensions, login items, privileged helpers, and launchd plists, with Apple application analysis.
Repository main includes experimental Windows x64 Ghidra support for native x86 and x86-64 PE applications on local NTFS, with bundled Job Object, private-DACL, and path-admission controls. Native x86 support requires the main implementation until its next npm release; published versions through 5.0.0 admit x86-64 targets. Check the release boundary before choosing a package version. See Windows Ghidra P0 for prerequisites and verified scope.
If something is not working, run:
npx -y rea-agents@latest doctor
doctor checks your host, dependencies, analysis tools, and agent configuration without changing them. Use --json for structured diagnostics.
On macOS, setup can install Hopper in ~/Applications after approval. It verifies the official download and does not need Homebrew or administrator privileges.
On supported Linux distributions, setup can install Hopper and its demo-session dependencies through your system package manager. You may see a system authorization prompt. Demo sessions use a private virtual display, leaving your desktop alone. See Hopper installation for download verification and platform details.
REA prefers an executable /opt/hopper/bin/Hopper on Linux. If it is unavailable, REA automatically checks ~/.local/share/rea/hopper/bin/Hopper. If Hopper was installed elsewhere:
export HOPPER_LAUNCHER_PATH=/absolute/path/to/Hopper
rea doctor --json
If doctor reports a missing analysis engine even though the file exists, inspect shared-library resolution with:
ldd /absolute/path/to/Hopper | grep 'not found'
Install the missing packages and rerun rea setup. The Linux demo needs Xvfb, Python 3, X11, and XTEST; approved setup installs these dependencies. If you use the curl installer, add ~/.local/bin to your shell PATH when needed.
Showing a partial view of a very large repo.
FAQ
rea is a Claude Code plugin with 1 hand-picked skill for security work, indexed on Flowy. Install it with the command on its page. It includes reverse-engineer-anything. Its skills do not fire on their own yet. Request auto-invocation to have Flowy route them as you prompt. Free and open source.
Is this plugin yours?
Claim it with GitHubSubmit a pluginPromote it