2026-10-10
What is REA (Reverse Engineer Anything)?
REA stands for Reverse Engineer Anything. It is an open-source project (morluto/rea, MIT) that exposes reverse-engineering capabilities to coding agents through the Model Context Protocol (MCP) and a CLI (rea-agents on npm).
In plain language: you point your agent at a local target you are allowed to analyze, and REA supplies structured tools — strings, symbols, decompilation (via a native engine you already own), JavaScript/Electron static graphs, and related inventory — so the agent can explain how the software works instead of guessing from marketing pages.
What it is not. REA is not a crack tool, not a DRM bypass, and not a substitute for owning Hopper, Ghidra, or IDA when you need deep native analysis. Native providers are bring-your-own. Static JavaScript inspection does not require those engines.
Who it is for. Security researchers, malware analysts under authorization, maintainers recovering behavior of their own shipping artifacts, and developers debugging closed packages they have rights to inspect. Always confirm license, contract, and local law before analyzing third-party software.
Upstream sources. Project home: github.com/morluto/rea. Install on this site: /docs/install/. Package: npm rea-agents.