An open-source project called Reverse Engineer Anything (REA) is taking coding agents into territory that has traditionally required highly specialized tools and expertise: reverse engineering applications and binaries. The project connects agents such as Claude Code, Codex, Cursor, and Gemini CLI with tools including Ghidra, Hopper, and IDA, allowing them to investigate how software works without access to its source code.

The key points about REA and agent-powered reverse engineering in 30 seconds

  • REA connects AI agents with tools for analyzing binaries, JavaScript, Electron, .NET, Android, and websites.
  • It can trace calls, modules, references, instructions, and other clues to build evidence-based explanations.
  • Analysis can run locally and returns both the evidence and the limitations behind each conclusion.
  • Its real-world showcases include analyzing Notion’s clipboard implementation and reconstructing functions from older games.
  • Initial setup can be completed with npx rea-agents setup and requires user approval.

The idea behind REA is not to ask an AI model to guess how a program works. Instead, it connects the agent to analysis tools already used by reverse-engineering specialists and feeds the resulting data back into the agent so it can continue the investigation.

That distinction significantly changes the scope of the project. An agent can receive a question about an application, run different analyses on its components, follow references and calls, gather evidence, and then explain what it has found. It can also use that information to write and test a similar implementation.

The project is available as open-source software and can be used from the terminal or through integrations with coding agents. Its configuration uses the Model Context Protocol (MCP), which allows agents to connect to external analysis tools.

From Claude Code to Ghidra in the same workflow

The initial REA setup can be completed with Node.js and npm using a single command:

npx rea-agents setup

The setup process lets users select which agents they want to connect, review the proposed configuration changes, and approve them. It then registers the MCP server and the corresponding workflow instructions.

The project supports Claude Code, Codex, Cursor, Gemini CLI, Grok Build, and other agents. For native analysis, REA can use an existing installation of Hopper, Ghidra, or IDA. It can also install Hopper during setup if the user approves it.

REA Turns Reverse Engineering Into a Task AI Coding Agents Can Execute | rea hopper analysis
REA Turns Reverse Engineering Into a Task AI Coding Agents Can Execute

For JavaScript or Electron applications, the barrier to entry is lower. Static analysis does not require one of those reverse-engineering engines and can work directly with an extracted application or an ASAR archive.

For example, the project provides a command for analyzing an application:

npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --json

The result can include modules, imports, Electron boundaries, and the evidence used to reach those conclusions.

This makes it possible to ask questions that previously required several tools to be combined manually. A developer can ask an agent to investigate a specific function, trace its path through an application, and explain what happens at each stage.

REA does not replace Ghidra, Hopper, or IDA. It brings them into a workflow where an agent can use them as part of a broader investigation.

What REA can analyze

The project’s current scope goes well beyond native executables.

For native binaries, it can return pseudocode, assembly, strings, symbols, calls, and references. For JavaScript and Electron applications, it can analyze modules, imports, source maps, routes, inter-process communication (IPC), and relationships with native add-ons.

It can also analyze .NET assemblies, Android applications, firmware, packages and resources, websites, network captures, and certain process records.

On Android, for example, it can work with APK files and retrieve information about manifests, classes, decompiled methods, and references. For .NET, it can inspect metadata, Common Intermediate Language (CIL) instructions, and native dependencies.

The project’s approach is to keep analysis results and evidence separate from the agent’s conclusions. REA returns the findings generated by the underlying tools so the model can reason about them, while also exposing the limitations behind each conclusion.

That matters in reverse engineering because generated pseudocode from a binary is not automatically equivalent to the original source code. Names may have been stripped, compiler optimizations may have changed the structure, and different implementations can produce similar instructions.

From Notion to classic games

REA’s showcase projects demonstrate how far this approach can go when analysis tools and coding agents are combined.

One example examines Notion’s clipboard implementation. REA follows the clipboard interface from the Electron renderer process through preload and IPC into the main process, allowing the implementation and the rich clipboard format to be investigated.

Another case reconstructs a function related to sound positioning in DX-Ball. The analysis follows a call into a function that calculates audio panning, examines the instructions, and uses the resulting information to reconstruct an implementation in C.

According to the project, that reconstruction passed 3,205 cases from the original code and reproduced all 63 bytes of the compiled function.

There is also a showcase dedicated to TH04, a game for the PC-98. REA analyzes 16-bit instructions, recovers calculations related to angles, and compares the reconstructed C++ code with historical compiler output.

These examples help explain what “reverse engineer anything” actually means in this project. It does not mean automatically recovering the original source code from any application. Instead, it gives an agent tools to observe a system, form hypotheses, search for evidence, and reconstruct specific parts of its behavior.

The project also includes an important warning: REA is intended for legitimate research and analysis, and users are responsible for obtaining the necessary authorization and complying with applicable laws.

Reverse engineering starts to look like a conversation

The most interesting part of REA is not that it has invented a new binary-analysis technique. Ghidra, IDA, and Hopper have provided powerful reverse-engineering capabilities for years.

What changes is the interface between those tools and the developer.

Instead of starting by opening a binary and manually navigating functions, references, and assembly, an agent can receive a question in natural language and use the available tools to investigate the problem. The developer can ask for evidence, challenge a conclusion, and then request an implementation based on what has been discovered.

That model fits particularly well with today’s coding agents because investigation and code generation no longer have to be completely separate processes.

The boundary, however, remains the quality of the evidence. An agent can accelerate analysis, but it does not turn a reconstruction into an exact copy of the original source code or remove the limitations of the underlying tools.

That is precisely what REA demonstrates: part of reverse engineering can move from a sequence of manual operations to a workflow guided by natural-language instructions. For developers who need to understand third-party applications, investigate legacy software, or study the behavior of an authorized binary, that difference could be substantial.

And perhaps the detail that best captures the shift is the simplest one: getting the workflow started begins with npx rea-agents setup.

Frequently Asked Questions

What is Reverse Engineer Anything?

Reverse Engineer Anything (REA) is an open-source project that connects coding agents with tools for analyzing applications, binaries, and other software artifacts. It returns results and evidence that the agent can use to investigate and explain how they work.

Which agents are compatible with REA?

The project lists Claude Code, Codex, Cursor, Gemini CLI, Grok Build, and other agents as supported. The documentation maintains the current list of compatible providers.

Does REA recover an application’s original source code?

Not necessarily. It can produce pseudocode, assembly, and reconstructed implementations, but the original source may have been lost or transformed by compilers and optimizations.

Do you need Ghidra, Hopper, or IDA?

For certain native-binary analyses, one of those analysis engines is required. Static JavaScript and Electron analysis, however, can be performed without a native reverse-engineering engine.

Scroll to Top