morluto / rea

REA: Reverse Engineer Anything

REA: Reverse Engineer Anything

One MCP for reverse engineering across binaries, applications, and runtime behavior. See a feature you like. Understand how it works, down to the binary level.

REA 是一个用于跨二进制文件、应用程序和运行时行为进行逆向工程的 MCP(Model Context Protocol)。看到你喜欢的功能?深入了解它是如何工作的,直至二进制层面。


Quick start · Current status · Investigation model · Tool catalog · Roadmap · How it works

快速开始 · 当前状态 · 调查模型 · 工具目录 · 路线图 · 工作原理

npx rea-agents setup


Join the Reverse Engineering Community Discord · Q&A · Show and Tell

加入逆向工程社区 Discord · 问答 · 展示与分享

See a feature in an app that you want in your own product? Ask your agent to investigate it with REA. It can inspect the app without its source code, explain how the feature works, show the evidence, and build a version for your project.

在某个应用中看到了想要集成到自己产品里的功能?让你的 AI 代理使用 REA 进行调查。它可以在没有源代码的情况下检查应用程序,解释功能的工作原理,展示证据,并为你的项目构建一个版本。

REA connects your agent to tools for inspecting native binaries, JavaScript and Electron apps, .NET assemblies, and websites. You can also use the same tools from your terminal. Analysis runs locally, and results include the evidence and limitations behind each conclusion.

REA 将你的代理连接到用于检查原生二进制文件、JavaScript 和 Electron 应用、.NET 程序集以及网站的工具。你也可以直接从终端使用这些工具。分析在本地运行,结果包含每个结论背后的证据和局限性。

Setup registers REA with your agent and installs matching workflow instructions. Native analysis can use an existing Hopper or Ghidra installation; setup can optionally install Hopper with approval. Static JavaScript analysis needs neither engine.

安装程序会将 REA 注册到你的代理中,并安装相应的流程指令。原生分析可以使用现有的 Hopper 或 Ghidra 安装;安装程序可以在获得许可的情况下选择性安装 Hopper。静态 JavaScript 分析不需要这些引擎。


Quick start

快速开始

Run setup (recommended) Set up REA with your agent: npx rea-agents setup

运行安装程序(推荐) 使用你的代理设置 REA: npx rea-agents setup

Choose which supported agents should use REA, then review the exact paths and changes before approving. Existing REA registrations are selected by default; newly detected agents are available to select, but detection alone does not select them. Setup adds MCP access and REA’s guided workflow for selected agents. Hopper is a separate optional choice with its own consent. Setup can also record an existing Ghidra installation. Setup shows its changes before applying them and backs up existing configuration. See Installation and setup for requirements and setup options.

选择哪些受支持的代理应使用 REA,然后在批准前审查具体的路径和更改。现有的 REA 注册默认会被选中;新检测到的代理可供选择,但仅被检测到并不会自动选中它们。安装程序会为选定的代理添加 MCP 访问权限和 REA 的引导式工作流。Hopper 是一个单独的可选项目,需要单独授权。安装程序还可以记录现有的 Ghidra 安装。安装程序会在应用更改前显示更改内容,并备份现有配置。有关要求和设置选项,请参阅“安装与设置”。


AI Coding Assistants (optional)

AI 编程助手(可选)

Add the skill to your AI coding assistant for richer context: npx skills add morluto/rea --skill reverse-engineer-anything

将此技能添加到你的 AI 编程助手以获取更丰富的上下文: npx skills add morluto/rea --skill reverse-engineer-anything

The skill provides REA’s investigation workflow. Run setup above to connect REA to your agent and configure analysis tools. Setup already installs a version-matched skill by default; this command installs the repository version.

该技能提供了 REA 的调查工作流。运行上述安装程序以将 REA 连接到你的代理并配置分析工具。安装程序默认已安装版本匹配的技能;此命令用于安装仓库版本。


使用代理(推荐)

After setup, restart your agent and describe the app or feature you want to understand. Hopper can run in demo mode; if it shows a first-run prompt, choose the demo or enter an existing license. REA supports Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf, Devin, OpenCode, Antigravity, GitHub Copilot CLI, Command Code, and VS Code. Existing REA registrations are selected by default during setup; other detected agents remain unselected until chosen. Other agents can use the manual MCP configuration.

设置完成后,重启你的代理并描述你想要了解的应用或功能。Hopper 可以以演示模式运行;如果出现首次运行提示,请选择演示或输入现有许可证。REA 支持 Claude Code、Claude Desktop、Codex、Cursor、Gemini CLI、Windsurf、Devin、OpenCode、Antigravity、GitHub Copilot CLI、Command Code 和 VS Code。在设置过程中,现有的 REA 注册默认会被选中;其他检测到的代理在被选中前保持未选中状态。其他代理可以使用手动 MCP 配置。


First result from the terminal

终端首个结果

For your extracted JavaScript/Electron application tree or ASAR, run: npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --json

对于你提取的 JavaScript/Electron 应用程序树或 ASAR 文件,运行: npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --json

Replace the path with your target (for example, “D:/apps/example” on Windows). This returns inline Evidence, recovered graph, limitations, and unknowns without MCP setup, Hopper, Ghidra, or executing the application. For a native app, configure its engine first, then use analyze with that app’s path. Run doctor when you need diagnosis; it is not a prerequisite for each analysis.

将路径替换为你的目标(例如 Windows 上的 “D:/apps/example”)。这将返回内联证据、恢复的图表、局限性和未知信息,无需 MCP 设置、Hopper、Ghidra 或执行应用程序。对于原生应用,请先配置其引擎,然后使用该应用的路径进行分析。当你需要诊断时运行 doctor;它不是每次分析的先决条件。


Install the rea command

安装 rea 命令

Install the command-line interface: curl -fsSL https://raw.githubusercontent.com/morluto/rea/main/install.sh | bash

安装命令行界面: curl -fsSL https://raw.githubusercontent.com/morluto/rea/main/install.sh | bash

The installer adds rea to your system and starts setup when run in a terminal. It requires Node.js and npm to be installed already. Alternatively, install with npm, then run setup: npm install --global rea-agents rea setup

安装程序会将 rea 添加到你的系统,并在终端运行时启动设置。它要求已安装 Node.js 和 npm。或者,使用 npm 安装,然后运行设置: npm install --global rea-agents rea setup

Update either installation with rea update.

使用 rea update 更新任一安装方式。


Requirements

要求

Static JavaScript inspection requires the Node/npm runtime only. Host and external-tool prerequisites depend on the selected workflow; the native provider guides describe their supported platforms.

静态 JavaScript 检查仅需要 Node/npm 运行时。主机和外部工具的先决条件取决于所选的工作流;原生提供程序指南描述了它们支持的平台。

  • macOS 12 or newer

  • Ubuntu 24.04+, Fedora 41+, or 64-bit Arch Linux

  • Node.js 22.x (>=22.19), 24.x (>=24.11), or 26+

  • npm; REA does not require or install a particular npm version

  • macOS 12 或更高版本

  • Ubuntu 24.04+、Fedora 41+ 或 64 位 Arch Linux

  • Node.js 22.x (>=22.19)、24.x (>=24.11) 或 26+

  • npm;REA 不需要也不安装特定的 npm 版本

Deep native binary analysis requires Hopper, Ghidra, or IDA Pro. Hopper is separate software with its own license; its demo supports analysis with vendor-defined limits. Ghidra and IDA are bring-your-own providers.

深度原生二进制分析需要 Hopper、Ghidra 或 IDA Pro。Hopper 是具有独立许可证的软件;其演示版支持在供应商定义的限制内进行分析。Ghidra 和 IDA 需要用户自行提供。

Firmware region inspection and explicit extraction use caller-supplied Binwalk and Unblob on Linux. See Firmware analysis for setup, provenance, resource limits and native handoff.

固件区域检查和显式提取在 Linux 上使用调用者提供的 Binwalk 和 Unblob。有关设置、来源、资源限制和原生移交,请参阅“固件分析”。

Static APK analysis uses a separately supplied headless JADX JAR and Java, with no emulator or APK execution. See Android analysis for setup, CLI/MCP operations, coverage and public test fixtures.

静态 APK 分析使用单独提供的无头 JADX JAR 和 Java,无需模拟器或 APK 执行。有关设置、CLI/MCP 操作、覆盖范围和公共测试夹具,请参阅“Android 分析”。

Repository main and npm 4.1.0 include experimental Windows x64 Ghidra support for native x86-64 PE applications on local NTFS, with bundled Job Object, private-DACL, and path-admission controls. Check the release boundary before expecting this from an older npm package. See Windows Ghidra P0 for prerequisites and verified scope.

仓库主分支和 npm 4.1.0 包含对本地 NTFS 上原生 x86-64 PE 应用程序的实验性 Windows x64 Ghidra 支持,并捆绑了作业对象 (Job Object)、私有 DACL 和路径准入控制。在期望旧版 npm 包支持此功能前,请检查发布版本。有关先决条件和验证范围,请参阅“Windows Ghidra P0”。

If something is not working, run: npx -y rea-agents@latest doctor doctor checks your host, dependencies, analysis tools, and agent configuration without changing them. Use —json for structured diagnostics.

如果出现问题,请运行: npx -y rea-agents@latest doctor doctor 会检查你的主机、依赖项、分析工具和代理配置,而不会更改它们。使用 --json 获取结构化诊断信息。


Linux installation and troubleshooting

Linux 安装与故障排除

On macOS, setup can install Hopper in ~/Applications after approval. It verifies the official download and does not need Homebrew or administrator privileges. On supported Linux distributions, setup can install Hopper and its demo-session dependencies through your system package manager. You may see a system authorization prompt. Demo sessions use a private virtual display, leaving your desktop alone. See Hopper installation for download verification and platform details.

在 macOS 上,安装程序可以在获得许可后将 Hopper 安装在 ~/Applications 中。它会验证官方下载,不需要 Homebrew 或管理员权限。在受支持的 Linux 发行版上,安装程序可以通过你的系统包管理器安装 Hopper 及其演示会话依赖项。你可能会看到系统授权提示。演示会话使用私有虚拟显示器,不会影响你的桌面。有关下载验证和平台详细信息,请参阅“Hopper 安装”。

The normal Linux launcher is /opt/hopper/bin/Hopper. If Hopper was installed elsewhere: export HOPPER_LAUNCHER_PATH=/absolute/path/to/Hopper rea doctor --json

Linux 的常规启动路径是 /opt/hopper/bin/Hopper。如果 Hopper 安装在其他位置: export HOPPER_LAUNCHER_PATH=/absolute/path/to/Hopper rea doctor --json

If doctor reports a missing analysis engine even though the file exists, 如果 doctor 报告缺少分析引擎,即使文件确实存在,