REA

Open-source MCP and CLI toolkit that connects AI agents to local analysis of native binaries, Electron apps, .NET assemblies, websites, firmware and captures.

Application SecurityOpen sourceSelf-hosted
Visit official website

Published Updated

CategoryApplication Security
AccessSelf-hosted
PricingOpen source
APIAvailable
Overview

What is REA?

REA, short for Reverse Engineer Anything, is an open-source orchestration layer that connects AI coding agents and command-line workflows to local reverse-engineering tools. It can coordinate supported providers such as Hopper, Ghidra and IDA for native binaries while providing dedicated paths for JavaScript, Electron, .NET, websites, firmware and recorded network traffic.

Read the full overview

The toolkit returns findings with evidence and limitations instead of treating an agent explanation as ground truth. Depending on the target, evidence can include pseudocode, assembly, symbols, call sites, imports, strings, source-map locations, IPC paths, terminal output or observed filesystem changes. Reviewers can follow those references and reproduce a narrower claim.

REA can be registered with compatible agents through MCP or used directly from its CLI. Analysis occurs on local tools, but evidence returned to a hosted model follows the model provider and client policy. Use it only on artifacts you are authorized to inspect. Read the ITHub technical analysis of REA for setup, evidence handling and security boundaries.

Why teams use it

Key capabilities

  • MCP integration for coding agentsConnect Codex, Claude Code, Cursor and other compatible clients to named analysis tools instead of relying on screenshots or unstructured shell output.
  • Native binary providersRetrieve pseudocode, disassembly, symbols, strings, callers, callees and references through a configured Hopper, Ghidra or IDA workflow.
  • JavaScript and Electron inspectionMap bundles, modules, imports, source maps, routes, preload boundaries, IPC channels and native add-ons without first running the target application.
  • .NET and artifact analysisInspect assembly metadata, CIL instructions and native dependencies, then hand off firmware, Android or archive formats to documented specialist tools.
  • Browser and capture workflowsRecord page structure, scripts, screenshots and network behavior or inspect saved HAR and supported mitmproxy captures as reviewable artifacts.
  • CLI automation and setup safeguardsRun targeted analyses outside an agent chat. The setup flow previews configuration changes and creates backups before registering clients.
Core areas

Authorized application security

Trace a vulnerability, data path or trust boundary in a controlled target while preserving the offsets, symbols and provider output used to reach the conclusion.

Compatibility engineering

Recover one observable behavior from a legacy or third-party component, implement a small interoperable replacement and compare it against known inputs rather than attempting an unrestricted reconstruction.

Software archaeology

Navigate applications whose source is missing or incomplete, identify module boundaries and document what is established, inferred and still unknown.

Evidence-preserving research

Hash the original artifact, record tool and provider versions, and keep every runtime experiment separate from static inspection so another engineer can repeat the work.

Positioning

REA is not a decompiler and does not replace Hopper, Ghidra, IDA, JADX, Binwalk or other underlying tools. It provides a common evidence-oriented interface that helps an agent select those tools, navigate their output and assemble a reviewable investigation.

It fits application-security engineers, malware analysts in controlled environments, compatibility developers and teams investigating their own legacy software. It is a poor fit for broad, unsupervised analysis of an unknown executable on a production workstation.

Model output remains an interpretation. Optimized code, obfuscation, packing, dynamic behavior and missing symbols can all produce incomplete or misleading conclusions. A human reviewer must check the cited evidence before using it for a patch, attribution or security decision.

Why it matters

AI agents can search large artifacts and test hypotheses faster than a person navigating every tool manually. The operational risk is that a plausible explanation may survive without a traceable basis. REA makes evidence, provider identity and uncertainty part of the result.

That structure supports smaller, safer investigations: define one behavior, begin with static inspection, capture exact references, escalate to runtime observation only when required, and finish with a reproducible acceptance test.

Local analysis does not automatically keep all data local. Decompiled code, strings, screenshots and captures passed to an agent may leave the machine through its model provider. Use a disposable environment for untrusted artifacts, limit network and filesystem access, and confirm authorization and applicable law before analysis.

Deployment & technical details

Technical details

Access
Self-hosted
Source model
Open source
Founded
2026
Pricing model
Open source
API
Available
Source check
Primary source ↗ checked
Check with the publisher

Official resources

Before you shortlist

What to verify for your environment

Profile audiences: Developers, DevOps Engineers.

  • Confirm current features, licensing and support terms with the publisher.
  • Validate deployment, data location, access control, backup and recovery requirements.
  • Test integrations, export paths and a representative operational workflow before committing.
Community experience

Reviews of REA

No published reviews yet.

Loading review form…