Skip to content

REA: Reverse Engineer Anything with AI Agents & MCP

REA (morluto/rea) connects AI coding agents via MCP to Ghidra, Hopper, and ASAR to reverse engineer binaries and Electron apps into verifiable code.

Hoang Yell
Hoang Yell
11 min read
Tiếng Việt
REA: Reverse Engineer Anything with AI Agents & MCP

Ask an AI coding agent to rebuild a feature from an open-source repo, and it delivers in minutes. Ask that same agent to replicate a slick search indexer or clipboard sync from a proprietary desktop app, and it hits a brick wall. Without access to original source code, the model hallucinates plausible-looking functions based on guesswork and marketing copy.

Feeding raw binary dumps into an LLM context window fails just as fast. A single compiled binary generates megabytes of assembly instructions, blowing through context budgets and poisoning the model with low-level noise.

REA (Reverse Engineer Anything) by Morluto tackles this breakdown with an evidence-first architecture: an open-source CLI and Model Context Protocol (MCP) server that arms AI agents with sensory organs to inspect native binaries, Electron applications, .NET assemblies, and Android APKs on your local machine.


TL;DR

Quick Answer Box (Google Search Featured Snippet):

  • What is REA? REA (morluto/rea) is an agent-first reverse-engineering suite and Model Context Protocol (MCP) server that lets AI agents inspect compiled binaries, Electron bundles, and runtime behaviors locally without source code.
  • Why does it matter? Instead of guessing implementations, agents use 126+ specialized MCP tools connected to disassemblers like Ghidra, Hopper, and JADX to build an empirical Reconstruction Obligation Ledger that tracks proven contracts and verifies clean-room code against real test cases.
  • Current status: Active open-source project (October 2026, GitHub Trending #1). Ships via rea-agents on npm with full bridges for Ghidra, Hopper, IDA Pro, ASAR, and headless browser scenario captures.
  • Repository: morluto/rea (License: MIT, Node.js 22+)
  • Best for: Engineers building clean-room reimplementations, security researchers auditing closed third-party dependencies, and developers analyzing proprietary Electron or native desktop features.
  • Main trade-off: Heavy local prerequisites. Ghidra engine cold starts can take up to 330 seconds on large binaries, Hopper requires commercial licensing for interactive workflows, and Windows Ghidra support remains experimental.

Beginner Map (Mental Model)

Before inspecting the tool catalog, ground REA’s pipeline with an everyday physical analogy:

The Architectural Metaphor: Asking an LLM to reverse-engineer a binary by reading raw hex dumps is like asking an architect to reconstruct a skyscraper by looking at a dump truck full of crushed concrete dust. REA acts like a forensic structural ultrasound scanner: it locates the steel load-bearing pillars (call graphs, symbols, strings), marks which beams connect to what (xrefs and IPC channels), and hands the architect a blueprint checklist of what must be rebuilt before laying a single brick.


Part 1: Foundations (The Hallucination Trap)

The fundamental failure of standard LLMs in reverse engineering comes down to epistemic grounding: models predict tokens based on statistical likelihood rather than empirical verification.

When an engineer prompts an agent: “Look at this compiled Mach-O binary and tell me how its licensing check works”, the model invents conventional cryptographic validation routines. It invents function signatures that look standard in OpenSSL or WebCrypto, completely detached from the actual control flow in the binary.

REA eliminates this disconnect through three core design choices:

  1. Local-First Execution: Binaries never get uploaded to external cloud APIs. All decompilation, disassembly, and runtime tracing occur strictly on your local machine.
  2. Evidence-Backed Responses: Every conclusion an agent receives must link back to an immutable Evidence Bundle containing exact file offsets, assembly instructions, cross-references (xrefs: list of code locations that reference a symbol), or recovered source maps.
  3. Structured Slicing: Rather than dumping 500,000 lines of unreadable assembly into the context window, REA slices binary targets into targeted scopes using specialized traversal queries.
Term Pocket Definition (3-6 words)
MCP (Model Context Protocol) Open socket standard for AI agents
Disassembler Binary to assembly translation engine
Decompiler Machine code to high-level pseudocode
xrefs (Cross-References) Pointers linking code to symbols
ASAR Electron application archive package format
CIL Common Intermediate Language for .NET
Obligation Ledger Verified contract checklist for reconstruction

Part 2: Investigation (How REA Works Under The Hood)

REA is packaged as a Node.js CLI and MCP daemon (rea-agents). It organizes its capabilities into 12 tool families containing 126 strongly-typed MCP tools.

1. Zero-Friction Agent Setup

Bootstrapping REA into an existing coding agent takes a single terminal command:

# Register REA MCP server with Claude Code, Cursor, Codex, or Gemini CLI
npx -y rea-agents@latest setup

The setup wizard automatically detects local agent configuration files, registers the REA MCP endpoint, creates timestamped backups of existing settings, and configures provider paths for Ghidra, Hopper, or IDA Pro.

To inspect an extracted Electron bundle or desktop application directly from the terminal without launching an agent:

# Deconstruct an Electron application bundle and emit structured JSON
npx -y rea-agents@latest analyze-javascript-application /path/to/extracted/asar --json

2. The 12 Tool Families

Instead of forcing a single monolithic prompt, REA divides its surface into specialized domains:

  • direct (41 tools): Low-level disassembler proxies for procedure assembly, raw byte extraction, bookmarks, and symbol renaming.
  • enhanced (14 tools): High-level architectural analysis including trace_call_path, trace_feature, batch_decompile, and Objective-C/Swift class extraction.
  • electron (5 tools): Module boundary identification, IPC (Inter-Process Communication: communication channel between processes) tracking, and renderer preload isolation.
  • application (13 tools): Obligation ledger creation, source map recovery, and reconstruction coverage evaluation.
  • managed (7 tools): .NET assembly reflection and CIL bytecode inspection.
  • android (5 tools): Headless JADX decompilation and manifest analysis.
  • browser (12 tools): Chrome DevTools Protocol scenario captures and network HAR audits.

3. The Reconstruction Obligation Ledger

The defining innovation in REA is the Reconstruction Obligation Ledger. When an agent investigates a target, REA does not just return raw pseudocode:

// Core ledger evaluation loop in REA application layer
export const evaluateReconstructionObligationLedger = ({
  candidates,
  bundle,
  manifest,
  generationLimitations,
}: LedgerEvaluationOptions): ReconstructionObligationLedger => {
  const context = createEvaluationContext(candidates, bundle, manifest);
  const obligations = applyDependencyDiagnostics(
    candidates.map((candidate) => evaluateObligation(candidate, context)),
    context
  );
  return {
    obligations,
    coverage: obligationLedgerCoverage(obligations),
    status: obligationLedgerStatus(obligations),
  };
};

This ledger operates like a double-entry bookkeeping system for software architecture:

  1. Obligation Candidates: Every function signature, state boundary, and data structure discovered in the target is logged as an obligation that the clean-room code must satisfy.
  2. Evidence Linking: Each candidate requires cryptographic or structural evidence before it is marked resolved.
  3. Contradiction Detection: If decompiled pseudocode contradicts observed runtime network payloads, the ledger flags an explicit contradiction diagnostic.
  4. Coverage Score: The agent receives a real percentage representing how much of the target feature is mathematically proven versus unverified.

4. Real-World Case Studies

REA’s repository documents three complete engineering showcases that validate this architecture:

  • DX-Ball (Classic PC Game): Reconstructed the complex sound-pan calculation function from raw 32-bit x86 instructions into portable C. The clean-room implementation passed 3,205 original x86 test cases and matched all 63 compiled machine-code bytes exactly.
  • Notion Desktop: Traced the proprietary clipboard serialization bridge from the front-end renderer API, through the Electron preload sandbox, down to the main background process IPC channel.
  • TH04 (Touhou Lotus Land Story): Recovered the 16-bit DOS bullet-ring angle algorithm from PC-98 machine code using Ghidra’s DOS analyzer, compiling into modern C++ matching historical Borland C++ output.

Part 3: Diagnosis (The Rough Edges & Operational Traps)

REA is a serious forensic instrument, not a toy for casual vibe-coding. If you deploy it in production workflows, you will hit sharp operational constraints.

Operational Friction Profile:
- Ghidra Cold-Start Latency:    Up to 330 seconds on large binaries
- Standard MCP Timeout Limit:   Default 60 seconds (requires explicit timeout override)
- Memory Consumption:           2 GB to 6 GB RAM during headless disassembler runs
- Host Platform Symmetry:       Hopper works on macOS/Linux; Windows Ghidra is experimental

Community Discourse on X (Twitter)

Within 48 hours of reaching #1 on GitHub Trending, discussions across developer feeds on X revealed both enthusiasm and sharp production warnings:

REA hitting #1 on GitHub trending makes total sense. Having Claude Code drive Ghidra and ASAR unpackers directly through MCP saves hours of manual xref hunting. You ask what an Electron IPC bridge does and it actually returns the evidence chain.

While builders celebrated automated evidence gathering, senior security analysts and systems engineers emphasized critical limitations:

Beware the hype around AI reverse engineering. REA is a great MCP wrapper, but disassemblers produce huge amounts of noise. If your agent does not know how to scope its queries, it drowns in assembly and hallucinates function semantics. The obligation ledger is mandatory.

The 4 Major Traps You Must Plan For:

  1. The MCP Handshake vs Engine Import Deadlock: Connecting REA via MCP takes less than a second. However, opening a 100 MB binary with Ghidra triggers auto-analysis that can run for 300+ seconds. Standard MCP client libraries (such as Claude Desktop or older SDKs) time out after 60 seconds. You must configure client request timeouts to 360,000 ms or the initial binary_overview query fails.
  2. Context Window Exhaustion: Calling batch_decompile on a medium-sized module will dump 30,000 lines of raw C pseudo-code into your prompt. This exhausts context buffers and degrades model reasoning. Force your agent to use surgical queries (trace_feature, trace_call_path) rather than wide dumps.
  3. External Disassembler Prerequisites: REA does not bundle Ghidra or Hopper inside the npm package. You must install a complete JDK (Java Development Kit: runtime needed for Java programs) 21+ for Ghidra, or purchase a Hopper license for full decompilation features on macOS.
  4. Legal and Licensing Boundaries: Decompiling proprietary commercial software is strictly regulated. REA provides tools for clean-room interoperability research. Reverse-engineering proprietary binaries to extract copyrighted assets or bypass DRM mechanisms violates terms of service and software copyright laws.

Part 4: Resolution (Decision Matrix)

Use this breakdown to determine whether REA belongs in your current engineering toolchain:

Project Scenario Deploy REA Immediately Stick to Manual Tools / Source Code
Electron / Desktop Re-engineering Extracting undocumented IPC routes and preload security boundaries from desktop apps. Target provides documented REST APIs or public open-source repositories.
Clean-Room Interoperability Writing drop-in file parser replacements or protocol bridges matching closed specifications. Rebuilding standard web frontend interfaces from visual designs alone.
Closed Dependency Auditing Verifying if a third-party native SDK or npm dependency contains malicious telemetry. Basic npm package vulnerability scanning via Dependabot or Snyk.
Resource-Constrained Hosts Machine has 16 GB+ RAM and installed JDK/Ghidra toolchains ready for local indexing. Lightweight laptops with less than 8 GB RAM and minimal disk storage.

Final Take

REA transforms AI reverse engineering from an unreliable parlor trick into an auditable engineering discipline: by coupling disassembler engines through MCP and enforcing an empirical obligation ledger, agents stop guessing how software works and start proving it with code.


Student First Assignment

  1. Install the CLI tool globally: npm install --global rea-agents.
  2. Inspect the local diagnostic health of your environment: run rea doctor.
  3. Extract an open-source Electron application or test ASAR archive on your system.
  4. Run rea analyze-javascript-application /path/to/extracted/app --json and inspect the generated module hierarchy and IPC event boundaries.

Frequently Asked Questions (FAQ)

Does REA send my binaries to cloud servers?

No. REA operates completely on your local machine. Analysis, decompilation, and runtime profiling run locally. Only the summarized tool results and evidence queries flow to your configured AI agent according to your provider’s normal API policies.

Do I need a paid license for Hopper or IDA Pro to use REA?

No. REA supports Ghidra, which is completely free and open-source. Hopper and IDA Pro are supported as alternative native analysis providers, but you can run complete workflows using Ghidra alone.

Can REA analyze minified JavaScript without source maps?

Yes. REA includes dedicated JavaScript and Electron analyzers that reconstruct module dependency graphs, parse AST (Abstract Syntax Tree: syntax tree representation of code) nodes, and map IPC communication channels between renderer and main processes even when code is minified.

Which AI coding agents currently work with REA?

Any AI assistant supporting local Model Context Protocol (MCP) servers works with REA. The automated npx rea-agents setup command includes native configuration for Claude Code, Cursor, Codex, Gemini CLI, and Antigravity CLI.

Related posts