REA
REA gives your coding agent tools to inspect a program and explain what it does, from app behavior down to native binaries.
Visit shijianzhong/reaOverview
REA is a reverse engineering toolset that connects coding agents to tools for inspecting native binaries, JavaScript and Electron apps, .NET assemblies, and websites. It helps understand how a feature works, show supporting evidence, and build a version for another project. Analysis runs locally, and results include the evidence and limitations behind each conclusion.
Key Features
- Connects coding agents to tools for inspecting native binaries, JavaScript and Electron apps, .NET assemblies, and websites.
- Supports investigation workflows from an agent or from the terminal.
- Runs analysis locally and returns evidence, limitations, and unknowns with each conclusion.
- Can use an existing Hopper, Ghidra, or IDA Pro installation for deep native binary analysis.
- Offers setup that registers REA with supported agents and installs matching workflow instructions.
- Supports static JavaScript and Electron application analysis without Hopper or Ghidra.
Use Cases
- Investigate a feature in an app, understand how it works, and build a version for your own project.
- Inspect native binaries, JavaScript and Electron applications, .NET assemblies, and websites.
- Analyze browser or runtime activity and compare results across runs.
- Study examples such as Windows Calculator percentage behavior, Chrome dinosaur game speed, DX-Ball reconstruction, Notion clipboard handling, and CTF flag checkers.
Getting Started
- Run npx rea-agents@latest setup or npx rea-agents setup to register REA with your agent.
- Choose which supported agents should use REA, review the exact paths and changes, and approve the setup plan.
- Restart your agent after setup, then describe the app or feature you want to understand.
- Optionally add the skill to your AI coding assistant with npx skills add morluto/rea --skill reverse-engineer-anything.
- For a first terminal result on an extracted JavaScript/Electron application tree or ASAR, run npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --json.
Deployment & Requirements
- Static JavaScript inspection requires the Node/npm runtime only.
- Supported platforms include macOS 12 or newer; Ubuntu 24.04+, Fedora 41+, 64-bit Arch Linux, or CachyOS.
- Node.js 22.x (>=22.19), 24.x (>=24.11), or 26+ is required; npm is required but no particular npm version is required or installed.
- Deep native binary analysis requires Hopper, Ghidra, or IDA Pro.
- Firmware region inspection and explicit extraction use caller-supplied Binwalk and Unblob on Linux.
Before You Adopt
- License: MIT. Review its terms before using, modifying, or distributing the project.
- Deep native binary analysis depends on external analysis engines; Hopper is separate licensed software with demo limits, while Ghidra and IDA are bring-your-own providers.
- Ghidra analysis can be slow on first query because it starts import and auto-analysis, which may exceed a client's default request deadline.
- Windows x64 Ghidra support is described as experimental in repository main.
- Native x86 support depends on the main implementation until the next npm release; published versions through 5.0.0 admit x86-64 targets.