The open-source project REA (Reverse Engineer Anything) connects reverse engineering tools to AI coding agents like Claude Code, Codex, Cursor, Gemini CLI, and Grok Build as an MCP service. Installation takes just one line, npx rea-agents setup, and it backs up your config before changing it and asks for your confirmation.
REA plugs reverse engineering tools into agents like Claude Code, Codex, and Cursor, and offers three verifiable reconstruction cases so you can judge whether this kind of analysis fits your own project.
REA: Let an AI agent help you reverse-engineer software without source code
The open-source project REA (Reverse Engineer Anything) connects reverse-engineering tools to AI coding agents like Claude Code, Codex, and Cursor. If you spot a nice feature in someone else's app, you can have the agent take that program apart, explain how the feature works, back it up with evidence, and then write something similar in your own project. Reverse engineering means working backward from a compiled program to figure out how it was written, without having the source code.
REA itself is an MCP service. MCP is the universal interface for AI agents to call external tools — once connected, the agent can call REA's analysis features directly in the conversation. Installation takes just one command, npx rea-agents setup, which registers it with agents like Claude Code, Codex, Cursor, Gemini CLI, and Grok Build, backing up your config and asking for confirmation before making changes. If you're not using an agent, you can also just run the commands directly in your terminal.
There's a lot you can analyze. Native applications—software compiled directly to machine code—require disassemblers like Hopper, Ghidra, or IDA to turn the machine code back into assembly and C-like pseudocode. Electron apps—desktop software built with web technologies, such as Notion—can be taken apart by unpacking the ASAR archive inside the installation package, letting you map out modules and inter-process communication without any extra tools. It also supports .NET programs, Android APKs, firmware, websites, packet captures, Ethereum contract bytecode, and recording program behavior at runtime on Linux and macOS.
The analysis runs locally. REA doesn’t upload the target program, but the results are sent to the model provider behind the agent, and how that data is handled depends on each provider’s policies.
The project covered three case studies. The first is the classic brick-breaker DX-Ball: starting from a single call that plays a sound effect, we traced it down to the function that computes the left and right audio channels from the ball's position, and reconstructed the incomplete pseudocode into C code. The 3205 sets of test results matched the original, and the compiled 63 bytes were identical to the original as well. The second is the Notion desktop app: we traced the full copy-paste path from the UI through the preload script and inter-process communication all the way to the main process. The third is the game Touhou Gensokyo (TH4) on an old Japanese PC-98: from 16-bit instructions, we recovered the angle algorithm behind the bullet rings.
For security researchers, people doing retro game remakes, and software preservationists, what used to mean reading disassembly line by line and tracing calls layer by layer can now start with an agent doing the tracing, while a human checks the evidence it produces. For ordinary developers who want to study how a competitor implemented a particular feature, there's now another path to explore.
The README shows the project already has 50000 stars on GitHub. The npm package first shipped in July this year, and the latest 6.3.0 version just went out today.
Two things to keep in mind before you use it. The project states that it only supports lawful reverse engineering, and that authorization and compliance are the user's own responsibility; reverse-engineering someone else's software may violate its terms of service or copyright law. The project also states that it has never issued or endorsed any cryptocurrency, and that any token borrowing the REA name has nothing to do with it.
https://github.com/morluto/rea
Source: 宝玉 · x.com