REA: Open-Source MCP Server Enabling AI Agents to Reverse Engineer Apps and Binaries Without Source Code

An in-depth look at REA (morluto/rea), an open-source CLI and MCP server that empowers AI coding agents to reverse engineer native binaries, Electron apps, and

tau · October 5, 2026

#REA #ReverseEngineering #MCP #AIAgents #ClaudeCode #Cursor #BinaryAnalysis #DevTools

REA: Open-Source MCP Server Enabling AI Agents to Reverse Engineer Apps and Binaries Without Source Code

During software development, teams frequently need to inspect how a feature works in another application to adapt and rebuild it within their own product. However, when source code is unavailable, analyzing compiled binaries or minified desktop and web bundles typically requires deep reverse-engineering expertise and considerable manual labor. Open-source developer morluto has released 'REA' (Reverse Engineer Anything), an open-source CLI and stdio Model Context Protocol (MCP) server designed to help AI coding agents investigate application behaviors, inspect native binaries, and rebuild desired features to match a project's specific stack and requirements.

Conceptual technical illustration of an AI coding agent analyzing application binaries and bundled code through the REA MCP server to reconstruct features

Image source: GitHub / morluto

Built with TypeScript and released under the MIT license, REA equips coding assistants—such as Claude, Cursor, and VS Code—with a unified, standardized interface for software investigation. Instead of forcing developers to orchestrate disparate reverse-engineering utilities manually, REA abstracts low-level analysis into a consistent workflow accessible directly over local CLI and stdio MCP channels.

Multi-Layer Reverse Engineering: From Native Binaries to Electron and Web Apps

REA provides agents with multi-layered inspection capabilities covering native desktop executables down to modern web and cross-platform application bundles.

  • Native Binary Analysis and Function Dossiers: On Linux, REA interfaces with Hopper decompiler or a user-provided Ghidra installation to run deep native analysis, producing comprehensive function dossiers detailing execution paths, logic, and interfaces.
  • Windows x64 Native PE Support: Provides an experimental Ghidra P0 path for analyzing approved native PE applications on Windows x64 environments.
  • Execution-Free Managed PE/CLI Triage: Allows agents to triage and inspect static metadata and structural properties of binaries safely without launching untrusted executables.
  • Node and Electron V8 Inspector Hooks: Connects to the V8 Inspector in Node and Electron runtimes, providing passive observation of live web pages and Electron windows to observe execution-context lifecycles and script metadata without active evaluation.
  • Bounded JavaScript and Source-Map Reconstruction: Reconstructs minified or bundled JavaScript assets alongside available source maps to recover module layouts and frontend architecture.

Verifiable Evidence v2 Records and Agent-Led Feature Reconstruction

A fundamental distinction between REA and standalone decompilers is its orientation around verifiable, evidence-backed engineering and feature recreation.

Throughout an investigation, REA records observed behaviors, disassembled routines, and execution traces into structured 'Evidence v2' artifacts. Rather than relying on transient conversational summaries prone to model hallucination, agents ground their analysis in concrete, inspectable evidence.

Using these Evidence v2 records, AI coding agents can grasp the underlying data structures, interfaces, and algorithms behind an existing application feature. The agent can then generate clean implementation code tailored to the user's preferred architecture, programming language, and styling conventions. This approach closes the loop between external software inspection and clean, in-repo feature reconstruction.

Installation Paths, Client Integration, and Operational Boundaries

REA is distributed officially through the npm registry, supporting both standalone command-line usage and stdio-based MCP connectivity.

  • Package Distribution: Published as the npm package rea-agents, containing both the unified CLI tool and the stdio MCP server.
  • MCP Client Integration: Because it operates over standard stdio, developers can register the server directly in configuration manifests for MCP-compatible environments, including Claude Code, Cursor, and VS Code extensions.
  • Open-Source Foundations: Licensed under MIT and implemented in TypeScript, allowing full source transparency and community auditing.

When adopting REA into practical agent pipelines, developers should account for its documented technical boundaries and operational considerations:

  1. Decompiler Prerequisites and Platform Maturity: Deep native binary decompilation relies on Hopper or a pre-installed Ghidra instance on Linux. On Windows x64, native PE analysis via Ghidra remains an experimental P0 capability with evolving coverage.
  2. Local Execution Context: Because the MCP server runs as a local stdio process inheriting the host user's privileges, analyzing unknown, unverified, or potentially untrusted binaries should always be conducted inside isolated containers, virtual machines, or sandboxed environments.

Sources