HomeTech NewsCybersecurityREA (Reverse Engineer Anything): What the Open-Source MCP Tool Does and What...

REA (Reverse Engineer Anything): What the Open-Source MCP Tool Does and What It Doesn’t

REA is an open-source project that gives an AI coding agent tools to inspect software it has no source code for. It runs as an MCP server and a command-line tool. This explainer covers what the project says it does, setup, limits and the legal side. TSN has not run it.

Spotted via @RohOnChain on X: https://x.com/RohOnChain/status/2109347169316839434. TSN did not verify the post’s claims and does not repeat them. Everything below comes from the project’s own pages and the other sources listed.

Confirmed: what the project’s pages say. Project claims: every statement about what REA can do is the project’s own. TSN did not run REA or test any claim.

Notice from the project’s README: “We have not issued or endorsed any cryptocurrency or token. Tokens using the REA name are not affiliated with the project.” [1]

What reverse engineering is

Reverse engineering means working out how software works by examining the finished program, not its source code. REA’s site defines it as “Finding out how software works by examining the program itself.” [5] By hand, a person reads low-level machine instructions and follows the calls between them.

What MCP is

MCP (Model Context Protocol) is “an open-source standard for connecting AI applications to external systems”, which its site compares to “a USB-C port for AI applications” [8]. You build MCP servers “to expose your data and tools” [8]. A tool is one action an agent can ask for. The agent asks, the server does the work, and the result goes back to the agent. REA is one such server. See Related stories for TSN’s earlier MCP explainers.

What the project says REA does

The README says: “REA connects your agent to tools for inspecting native binaries, JavaScript and Electron apps, .NET assemblies, and websites.” It adds: “Analysis runs locally, and results include the evidence and limitations behind each conclusion.” [1]

Its coverage table lists, among others [1]:

  • Native binaries: pseudocode, assembly, strings and calls. Needs Hopper, Ghidra or IDA.
  • JavaScript and Electron apps: modules, imports and source maps. Needs Node.js and npm.
  • Websites: page structure, scripts and network observations. Needs a Chrome-family browser.
  • .NET assemblies: metadata and CIL instructions. Static only.

“Local” has a limit. The README FAQ says: “REA analyzes targets locally. Your agent receives the tool results, and its model provider has its own data policy.” [1] In plain words, the app is not sent to an REA service, but what the tools find goes to your agent, and its AI provider has its own rules.

Hopper is “separate commercial software with its own license”; its free demo “has vendor-defined limits” [3].

How it works: the Calculator example

The README’s flow: “Your agent calls REA through MCP to inspect the target and trace relevant code. REA returns findings with their evidence.” [1]

REA’s site shows one worked case: why does Windows Calculator give 220 for 200 + 10%? The prompt shown is “Use REA to inspect Windows Calculator’s % button. Recover the rules after + and ×, then build a small calculator that uses both.” [5] The site then lists three steps [5]:

  1. REA reads calc.exe. It launches the Calculator app, and the agent selects the installed app’s library.
  2. REA returns the % handler’s code. The function “checks the operator and uses the constant 100”.
  3. The agent explains the rules and reproduces them, cross-checking the branch with Microsoft’s source.

The site shows selected instructions that compare a value with 0x5c and 0x5b and load 0x64. Using Microsoft’s public source, it maps these to the multiply and divide operator IDs and the number 100. Its readable summary: after × or ÷, the percentage is the number divided by 100. Otherwise it is the number times the first number, divided by 100. So 10% of 200 is 20, and 200 + 20 is 220 [5].

The caption reads “Inspected with REA 4.1.0: Windows Calculator 11.2508.4.0, x64.” The site says the summary “uses names from Microsoft’s public source” [5]. That is all the page shows: no timings, no failed attempts, no independent check. The npm registry lists 6.4.0 as the latest version [6].

Setup, as the project gives it

  1. Have Node.js 22.x (22.19 or later), 24.x (24.11 or later) or 26+, plus npm [1].
  2. Run npx rea-agents setup [1]. The site and installation guide also give npx rea-agents@latest setup [3][5].
  3. “Choose your agents, review the proposed changes, and approve them.” Setup “adds REA’s MCP server and matching workflow instructions, with backups of existing configuration.” [1]
  4. Restart your agent [1].
  5. For native analysis, “configure a provider first” [1]. Setup “can optionally install Hopper with approval” [1].

Supported agents include Claude Code, Codex, Cursor, Gemini CLI and Grok Build [1]. For others, the installation guide gives this manual entry [3]:

{
  "mcpServers": {
    "rea": {
      "command": "npx",
      "args": ["-y", "rea-agents@6.4.0", "mcp"]
    }
  }
}

The guide says: “Persistent registrations should use one exact package version.” [3]

Limits

  • Not tested by TSN. We did not run REA or check any result.
  • Platform support varies. “Native formats and host support vary by provider.” [1] Windows Ghidra support is “experimental” and “does not establish general Windows feature parity” [4].
  • Not original source. Provider pseudocode “is never treated as original source” [3]. The MCP listing says: “No decompiler can guarantee the original source code.” [7]
  • Not sandboxed. Runtime capture “runs or interacts with the selected target using your user permissions” [1]. Avoid pointing it at software you do not trust.
  • Pages disagree on coverage. The MCP listing calls APIs, protocols, mobile artifacts and firmware “longer-term” [7]. The GitHub README lists Android APKs and firmware as current targets [1]. The listing looks like older README text, so TSN follows the README.
  • Checking. TSN found no docs line telling users to verify findings by hand. TSN’s own advice: check the agent’s conclusions against the evidence REA returns.

Legal and licensing

The MIT licence covers REA itself: the LICENSE file is the standard MIT text with “Copyright (c) 2026 morluto” [2]. It does not cover the software you analyse, which keeps its own licence and terms.

Reverse engineering paid software can breach licence terms, copyright law or anti-circumvention law, depending on where you are. Exceptions for interoperability and security research are narrow. The Electronic Frontier Foundation’s FAQ (a US-focused guide for non-lawyers) says the anti-circumvention exceptions “are drafted very narrowly”, that licence terms raise risk, and that copying code into your own program “is highly risky” [9]. EFF says its FAQ is “not legal or technical advice” and “does not address international or foreign law” [9].

The project’s disclaimer says: “You are responsible for obtaining any required authorization and complying with applicable laws. The project does not endorse illegal or unauthorized use.” [1]

TSN does not endorse bypassing paid features or licence checks. This is not legal advice. For a specific case, ask a qualified lawyer.

Sources

  1. morluto, “REA: Reverse Engineer Anything”, GitHub repository and README (primary; description “Reverse engineer anything with agents, from app behavior down to native binaries.”; MIT per GitHub API; read 11 October 2026). https://github.com/morluto/rea
  2. morluto/rea, LICENSE file (read 11 October 2026). https://raw.githubusercontent.com/morluto/rea/HEAD/LICENSE
  3. morluto/rea, docs/installation.md (primary; read 11 October 2026). https://github.com/morluto/rea/blob/main/docs/installation.md
  4. morluto/rea, docs/windows-ghidra-p0.md (primary; read 11 October 2026). https://github.com/morluto/rea/blob/main/docs/windows-ghidra-p0.md
  5. REA project website (primary; Calculator example; read 11 October 2026). https://rea.tools/
  6. npm, rea-agents package (MIT; latest 6.4.0 per the registry; read 11 October 2026). https://www.npmjs.com/package/rea-agents and https://registry.npmjs.org/rea-agents
  7. MCP Repository, listing for morluto/rea (third-party mirror of project text; appears older than the GitHub README). https://mcprepository.com/morluto/rea
  8. Model Context Protocol, “What is the Model Context Protocol (MCP)?” (primary). https://modelcontextprotocol.io/docs/getting-started/intro
  9. Electronic Frontier Foundation, Coders’ Rights Project Reverse Engineering FAQ (general US guide; not legal advice). https://www.eff.org/issues/coders/reverse-engineering-faq
  10. @RohOnChain on X, 11 October 2026 (trigger only; claims unverified; not cited for any fact). https://x.com/RohOnChain/status/2109347169316839434

Related stories

Share this story

Latest stories

More in this category

Latest stories

Free TSN tools: AI funding tracker, DePIN scorecard, AI agent cost calculator and more.