
rea wires AI agents and a CLI into local reverse-engineering workflows, decompiling native binaries and mapping JavaScript applications for authorized analysis and feature research.
| Tool | morluto/rea — an agent-friendly reverse-engineering toolkit that connects CLI and MCP clients to Hopper and Ghidra for local analysis of apps and native binaries |
| Category | AI-assisted reverse engineering framework (CLI + MCP server, TypeScript, MIT) |
| Primary Use | Understanding how a feature works in an application you are authorized to inspect — Decompile, Understand, Recreate — with reproducible Evidence records, via rea analyze, rea decompile, and rea compare |
| Safe Use | Intended for authorized professionals: interoperability research, malware triage, security audit of software you own or are licensed to test, and lab-based education; local-only analysis keeps targets off hosted services |
| Telemetry Note | Runs entirely on the local host, writing ~/.rea/cache and ~/.rea/state plus Evidence files and captures; defenders can observe Hopper/Ghidra process launches, temporary project copies, and Xvfb demo sessions on Linux |
rea positions itself as a reverse-engineering harness built for the agent era: instead of a human operator choosing between a disassembler, a decompiler, and a scripting API, an MCP-connected coding agent gets a single, structured surface for investigating software. The pitch is deliberately scoped — see a feature you like in an app, ask the agent to explain how it works down to the binary level, and then have it build an adapted version for your own stack. The README is explicit about limits: rea does not claim to recover original source code or automatically clone an application, and every conclusion ships with its evidence and stated limitations. That epistemic honesty is rare in this category and immediately signals the project is aimed at serious, authorized work rather than shortcut-seeking.
The core investigation model is a three-stage loop labeled Decompile, Understand, and Recreate. Decompile opens a target and recovers readable code, strings, and symbol names; Understand follows control and data flow across the app until the agent can explain a concrete feature; Recreate turns that understanding into working code in the same coding session. The separation matters architecturally, because each stage produces structured intermediate results — including reproducible Evidence records — that the CLI can validate, canonicalize, and diff later via rea evidence-import, rea evidence-export, and rea compare. In practice this turns ad-hoc reversing sessions into auditable artifacts a team can review.
Under the hood, rea is a TypeScript package distributed as rea-agents on npm, requiring Node.js 22.19+ or 24.11+, running on macOS 12+ and modern Linux distributions. Native binary analysis is delegated to two external providers: Hopper, which setup can install with explicit consent, and a bring-your-own Ghidra adapter requiring Ghidra 12.1.4 and a 64-bit JDK 21. The Ghidra adapter exposes 22 read-only operations covering functions, strings, symbols, assembly, decompilation, calls, references, instructions, and data types, feeding rea's overview, search, call-graph, and function-analysis workflows. Notably, the adapter analyzes a temporary copy of the target and deletes the temporary project when the session closes — a clean-slate design that avoids mutating the original file.
Agent integration is where rea spends most of its setup effort, and the README describes an unusually careful consent model. The wizard detects Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf, Devin, OpenCode, Antigravity, GitHub Copilot CLI, and VS Code, but detection never implies selection — nothing is preselected, and each capability gets its own checklist. Registrations are additive, backup-first, and read back after writing. Devin is reported but deliberately left unconfigured because it lacks a documented local MCP configuration boundary — a thoughtful security judgment. A --dry-run flag previews the plan, --client selects exact agents, --json emits machine output, and declining at any prompt leaves the system unchanged.
Beyond native binaries, rea maps higher application layers. The tool catalog covers JavaScript and Electron applications without executing them, via rea analyze PATH and analyze-javascript-application, plus passive observation of websites, Electron pages, and Node/Electron V8 Inspector sessions, and JavaScript source-map reconstruction. The README also mentions execution-free managed PE/CLI triage for .NET assemblies and provider-neutral graphs that connect application layers while keeping static inference clearly separated from runtime observation. Windows Ghidra support remains explicitly experimental and unavailable pending process-ownership and safe-path controls documented in a dedicated windows-ghidra-p0 guide — the team is transparent that the hardening simply is not done yet.
Installation is conventional npm territory: npm install --global rea-agents followed by rea setup, or npx rea-agents setup for a run-first flow. A curl wrapper script exists but only starts setup when a terminal is available. Once installed, rea update handles upgrades, rea doctor validates host, dependencies, providers, and agent configuration without changing anything, and rea uninstall --purge-data removes only ~/.rea/cache and ~/.rea/state while preserving Hopper, Node.js, Evidence files, captures, and unrelated MCP servers. The uninstall path even refuses malformed client configuration and never follows purge-data symlinks — defensive coding that suggests the authors expected adversarial filesystem states.
The local-by-design commitment deserves emphasis for anyone doing sensitive work. Analysis runs on your supported local host and rea does not upload the target application to a hosted analysis service, which means proprietary binaries, licensed software, or suspected malware samples under authorized investigation never leave the analyst's machine. For defensive teams, this also sharpens the telemetry picture: Hopper launches under /opt/hopper/bin/Hopper on Linux (or the macOS app bundle path), Ghidra sessions create and destroy temporary projects, and Linux demo sessions run under a private Xvfb display with Python 3, X11, and XTEST dependencies — all observable signals for blue teams monitoring their own analysis workstations.
For operators, the practical fit is interoperability and comprehension research: understanding an undocumented file format, tracing how a competitor feature behaves in an app you are licensed to study, triaging a suspicious assembly without detonating it, or reconstructing minified JavaScript with source maps. The Evidence bundle workflow elevates rea above a chat wrapper — findings become comparable, exportable records that support a written report, which is exactly what authorized assessments and code-compliance audits demand. The compare command in particular enables before/after version diffing of conclusions as an app evolves.
Watch items are worth stating plainly. The project leans on Hopper's demo mode with vendor-defined limits unless you hold a license, and the Ghidra path pins specific versions (Ghidra 12.1.4, JDK 21), so drift will bite eventually. Windows users are effectively first-class nowhere yet: the Ghidra P0 is gated on unimplemented ownership and permission checks. The roadmap — APIs, protocols, mobile artifacts, firmware, richer runtime behavior — is ambitious and largely unshipped, so treat current capability as macOS/Linux native plus JavaScript/Electron/.NET triage. With roughly 5,600 stars, an MIT license, active CI, and multi-language READMEs, rea is a credible, well-engineered entry in the AI-assisted reversing space, best evaluated today for its evidence discipline rather than its breadth.
morluto/rea.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.