Reverse Engineer Anything (REA) Released: Open-Source MCP Bridge for Binary Analysis with Coding Agents
REA connects coding agents like Claude Code to Ghidra, Hopper, and IDA via MCP, automating binary inspection, decompiled function reading, and call tracing with
An open-source project named 'REA (Reverse Engineer Anything)' has been released, enabling coding agents to investigate application binaries and trace internal execution without access to original source code.

Image source: Tech with Mak (@techNmak)
Built on the Model Context Protocol (MCP), REA integrates modern coding agents such as Claude Code directly with local decompilers, turning manual binary inspection, decompiled function reading, and call-graph tracing into a structured agentic workflow.
MCP Architecture Bridging Decompilers and Coding Agents
Traditional reverse engineering requires security researchers and developers to manually navigate complex decompiler GUIs, cross-referencing function calls and data references step by step. REA introduces a standardized MCP interface to streamline this pipeline.
- Decompiler Ecosystem Support: Connects agents to industry-standard reverse-engineering tools including Ghidra, Hopper, and IDA via MCP bridges.
- Binary Inspection and Call Tracing: Allows agents to inspect binary layouts, read decompiled C-like pseudocode, and systematically trace function call graphs.
- Improved Analysis of Stripped Binaries: Helps agents understand variable roles and program flow based on architectural context rather than single-shot guessing on stripped symbols.
Demonstrated Case Studies: Notion IPC Tracing and DX-Ball Reconstruction
The REA project showcased concrete verification examples across real-world application binaries:
- Electron IPC Tracing in Notion: Successfully traced how the Notion Electron desktop application processes clipboard operations across internal IPC channels.
- DX-Ball Function Reconstruction and Test Validation: Reconstructed an internal function from the 1996 classic game DX-Ball and verified its correctness against 3,205 test cases extracted from the original x86 build.
Implementation Caveats and Environment Requirements
REA is designed as an analytical aid rather than an automated silver bullet for source-code recovery, and requires specific engineering discipline in practice:
- Human Analysis and Rigorous Validation: Inferences and reconstructed functions generated by agents must be validated against real test cases and engineering review.
- Local Decompiler Prerequisites: Requires pre-configured local installations of Ghidra, Hopper, or IDA alongside their corresponding MCP bridge endpoints.
- Execution Isolation and Security: When investigating untrusted binaries or suspected malware, running decompilers within isolated, network-gated environments is strongly advised.
Sources
- Tech with Mak on X (@techNmak): REA (Reverse Engineer Anything) Announcement and Case Studies