连接 Hopper/Ghidra 等逆向工具,通过 Agent 自动分析应用行为与二进制实现,支持本地运行并提供证据与局限性说明。
一个 MCP,贯穿二进制文件、应用程序和运行时行为进行逆向工程。
看到某个感兴趣的功能,就能理解它的工作原理,直至二进制层面。
Website · Guides · Showcases
Quick start · How REA works · What you can analyze · Showcases · FAQ · Documentation
看到某个 App 里的功能,想要集成到自己的产品中?让 Agent 用 REA 去调查。它可以在没有源码的情况下检查 App,解释功能的工作原理,展示证据,并为你的项目构建一个类似实现。
REA 将 Agent 连接到各种检查工具:原生二进制文件、JavaScript 和 Electron 应用、.NET 程序集以及网站。你也可以从终端直接使用这些工具。分析在本地执行,结果包含每个结论的依据(evidence)和局限性(limitations)。
Setup 向 Agent 注册 REA 并安装配套的工作流说明。原生分析可以使用已有的 Hopper 或 Ghidra 安装;setup 可以在授权后选择性安装 Hopper。静态 JavaScript 分析无需任何引擎。
访问 REA 网站获取安装说明、带插图的操作指南和真实案例。
安装 Node.js 和 npm 后,运行:
npx rea-agents setup
选择你的 Agent,审查拟议的更改,然后批准。Setup 会添加 REA 的 MCP server 和配套的工作流说明,并备份现有配置。之后重启 Agent。
Setup 支持 Claude Code、Codex、Cursor、Gemini CLI 等 Agent。参见安装和设置了解提供商配置及手动 MCP 注册。
Understand how search works in the Notes app, show me the evidence, and build a
similar feature for my project.
把 Notes 换成你的目标 App,把 search 换成你想了解的功能。
检查提取出的 JavaScript/Electron 应用目录或 ASAR:
npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --json
结果包含模块、导入、Electron 边界及其依据。将路径替换为你的目标,如 Windows 上的 "D:/apps/example"。
安装 rea 命令以便日常使用:
npm install --global rea-agents
rea --help
原生分析需先配置提供商。参见 CLI 和 Evidence 指南了解原生命令、提供商选择、快照和脚本。
REA 更新频繁,新版本包含频繁的 bug 修复。保持安装最新。
npm 安装的 CLI:
rea update
刷新 Agent 注册和 skill,运行 update 打印出的 setup 命令。
如果使用 npx,用以下命令更新 Agent setup:
npx rea-agents@latest setup
审查 setup 更改并重启 Agent。对于一次性 CLI 命令,使用 npx rea-agents@latest 后接命令。
Agent 通过 MCP 调用 REA 来检查目标并追踪相关代码。REA 返回附带依据的发现。Agent 用它们来追问、解释行为,或编写和测试实现。CLI 命令使用相同的工作流。
Open the full-size figure.
REA 需要 Node.js 22.x (>=22.19)、24.x (>=24.11) 或 26+,以及 npm。额外的工具和主机支持取决于目标:
静态 JavaScript 和 .NET 检查读取提供的文件,无需运行应用程序。运行时捕获使用你的用户权限运行或交互目标;每个运行时指南都描述了其影响。
原生格式和主机支持因提供商而异。参见 Hopper 和 Ghidra 设置、IDA 指南和实验性 Windows Ghidra 支持。Ghidra 还支持 16 位 DOS 分析。关于提供商选择,参见 CLI 指南。查看发布说明了解最新 npm 发布后添加的功能。
Follow a sound call into its position-to-pan helper, inspect the instructions, and turn incomplete pseudocode into C. The reconstruction passes 3,205 original-x86 cases and reproduces all 63 compiled function bytes.
Read the case study · Reconstruction repository
Find the renderer's clipboard API, follow it through preload and IPC into the main process, and inspect the rich clipboard format.
Inspect the original PC-98 game's 16-bit instructions, recover the fixed and aimed angle calculations, and compare the reconstructed C++ with the historical compiler output.
Read the case study · Reconstruction repository
If you've used REA on something interesting, we'd love to see it. Share your case in an issue or a pull request, including the target, your question, how REA helped, and what you found.
Any agent that supports local MCP servers. Setup configures the supported agents; other clients can use manual MCP registration.
Deep native analysis uses one of them. Static JavaScript and .NET inspection work without a native analysis engine. Setup can install Hopper after approval; Ghidra and IDA use your existing installations. See provider setup.
REA starts Hopper when an operation needs it. On macOS, a first-run dialog may ask you to choose demo mode or activate your license. See Hopper startup and troubleshooting.
The skill supplies investigation instructions for your agent. Use rea setup to register REA's MCP server and install the matching instructions, then restart your agent. See skill-only installation.
Native analysis returns pseudocode and assembly. JavaScript/Electron analysis recovers modules and their relationships. Your agent uses these findings to write and test an implementation; the showcases give worked examples.
REA analyzes targets locally. Your agent receives the tool results, and its model provider has its own data policy.
Update first; a recent release may already fix it.
For an npm-installed CLI:
rea update
For agent setup through npx:
npx rea-agents@latest setup
If you're using an agent, complete the setup refresh and restart it. Retry the same task. If the problem persists, open an issue with your REA version, target type, steps to reproduce and error output.
Start with the website's worked guides. For exact options, prerequisites and result contracts:
Installation and setup: agent registration, provider configuration, updates and uninstall.
Readiness and troubleshooting: diagnose one agent or analysis engine.
CLI and Evidence: commands, provider selection, snapshots, import/export and exit statuses.
MCP contracts and agent prompts: tool results, sessions and guided investigations.
Tool catalog: generated inventory of tools, providers and CLI commands.
Roadmap: planned work and capability trackers.
Report vulnerabilities through SECURITY.md.
We'd love your help with REA! Open an issue to report a bug or suggest a feature, or send a pull request to improve the code or docs.
See CONTRIBUTING.md for development setup and checks, testing for verification lanes, and the architecture map for the project structure.
Website · npm · skills.sh · Issues · Security
REA provides tools for lawful reverse-engineering research, analysis, and reconstruction. You are responsible for obtaining any required authorization and complying with applicable laws. The project does not endorse illegal or unauthorized use.