REA gives coding agents MCP tools to reverse engineer binaries and apps
REA, an MCP server that connects a coding agent to disassemblers, decompilers, and browser inspectors, reached 47,884 GitHub stars and released v6.0 with EVM bytecode, Windows PE, and crash inspection.

Image: REA (morluto/rea)
Why it mattersA developer who wants to copy how a feature works in a released product can now ask their agent to inspect the binary and show the evidence, in place of guessing from the user interface.
A developer who sees a feature they want to copy from a released app used to have two options: guess from the user interface, or learn the tools professionals use for taking an application apart. REA, short for Reverse Engineer Anything, gives a coding agent the second option as a set of callable tools. It is an MCP server that connects a coding agent to native disassemblers like Hopper, Ghidra, and IDA, plus browser inspectors, .NET decompilers, Android analysis tools, and more. The project's documentation lists every mainstream coding agent among the supported hosts. The project reached 47,884 stars on GitHub and released version 6.0 on 8 October 2026.
What the agent gets
Through REA's MCP tools, an agent can inspect native binaries (pseudocode, assembly, strings, symbols, calls, references) with a configured Hopper, Ghidra, or IDA. It can read JavaScript and Electron applications statically to recover modules, imports, source maps, routes, IPC, and native add-on relationships, without an analysis engine installed. It can take apart .NET assemblies, Android APKs with JADX, firmware images with Binwalk or Unblob, EVM bytecode, saved HAR and mitmproxy captures, and websites in a Chrome-family browser. Every finding comes back with its evidence and its limits.
Setup registers REA with the agent and installs matching workflow instructions. Native analysis can use an existing Hopper, Ghidra, or IDA install, or setup can install Hopper after the user approves. Static JavaScript and .NET inspection need nothing beyond Node.js.
What version 6 added
Version 6.0 added offline ELF layout inspection through pwntools, recorded crash inspection through pwntools and pwndbg, native x86 PE support on Windows through Ghidra, EVM bytecode inspection through EVMole, LLDB-based observation of function and Objective-C method calls, Mach-O dylib resolution in Apple bundles, and inspection of historical web network captures. The one breaking change: MCP filesystem inputs now require absolute host paths. Three more releases (v6.1 through v6.3) followed inside the next 24 hours.
The published showcases
The project links three worked examples a reader can follow in full. In DX-Ball, the agent follows a sound call into a position-to-pan helper, inspects the x86 instructions, and reconstructs the function in C: the result passes 3,205 original-x86 cases and reproduces all 63 compiled function bytes. In Notion, the agent traces the Electron clipboard bridge from the renderer through preload and IPC into the main process, and reads the rich clipboard format. The TH04 showcase reconstructs a Touhou bullet-ring routine. Every claim links to a repository the reader can run.
Why a reverse-engineering tool reads as agent news
The owner of a feature on a released product has every reason to keep its implementation private, and a developer trying to match that feature has every reason to understand it. Hopper, Ghidra, and IDA have been used for years by reverse engineers, so the capability itself is well established. The change is in who can use them: REA hands those tools to the model a developer already works with, through one install and one MCP contract. For a solo founder cloning a feature, or a researcher checking a vendor claim against the binary that carries it, the work that used to take a specialist now runs inside the agent they already use.
Source
REA on GitHub · rea.tools · v6.0.0 release notes. Capabilities and showcase figures: REA's own README and site. Star count: GitHub API.
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.