REA, Claimed Open-Source Reverse-Engineering Toolchain as MCP for Coding Agents
Follow-up posts describe REA as open source that reportedly wraps a reverse-engineering toolchain as a local MCP server for agents like Claude Code, Codex, and
On October 8, 2026, X user Chen Dahuang (@realchendahuang) introduced REA in a Chinese-language post as a project that reportedly exposes a reverse-engineering toolchain as a local MCP server. The "open-source" label comes from follow-up posts in the thread (@lxfater, @shijianzhongg), not from the original post text, and the bundle has no GitHub record to confirm the repository. The core claim is straightforward: let the agent call the RE tooling directly, so that when given an app or executable it walks symbol tables, strings, call graphs, and pseudocode, figures out the algorithm and control flow, and then reimplements it in the user's chosen stack.
What REA claims and what it connects to
According to the original post, REA bundles the whole RE toolchain as a local MCP service that connects directly to everyday coding agents such as Claude Code, Codex, and Cursor. The author frames agent-invoked tooling as the difference from manual reverse engineering.
- Claimed scope: unpacking Electron app asar archives, plus Mach-O, PE, and ELF binary analysis through local Hopper and Ghidra interfaces
- Recommended workflow (as claimed): hand the app or executable to the agent → explore symbols, search strings, follow the call graph, read pseudocode → understand the algorithm and control flow → reimplement it in your own project with your chosen stack
X user @lxfater broke the claimed coverage into three stages in a follow-up post the same day: reverse-engineering JavaScript/Electron apps to find modules and call relationships, decompiling Android APKs to inspect methods, and tracing native binaries down to functions, strings, and assembly. The example that post cites as official tracks a Notion copy operation down to system clipboard handling and rich-text storage.
Install path and unverified claims
The install procedure below comes from the @lxfater post only. With Node.js and npm installed, run npx rea-agents@latest setup, pick your agent when prompted, restart, and it connects, the post claims. Analyzing native binaries additionally requires setting up a tool such as Ghidra or Hopper.
Treat the following figures and attributes as single-post claims with no primary-source corroboration in the bundle:
- 7,744 new stars in one day, roughly 19,500 total stars
- MIT license
One repository caveat: the bundle has no GitHub record, and the t.co short links in the source posts were never expanded, so the canonical repository URL is unconfirmed. This draft does not carry the short links forward; confirm the canonical GitHub URL at the asset stage. The install command likewise comes from a single post without official-docs corroboration, so check the repository README for the command and the supported agent list before running it.
Who it is for
It is relevant to developers who want to verify what an app does behind the scenes, inspect suspicious software behavior, or study a well-built app's structure for learning. Reverse engineering is still bound by each target's license and local law. Start with targets you clearly have rights to analyze — your own apps, in-house binaries, or open-source builds — and keep tool-call and export logs. One reply to the original post raised the same point: set guardrails first, such as a read-only default scope and an audit trail.