Dev & Engineering

REA Tool Design Skill

A specification skill for designing or changing REA investigation tools, CLI/MCP contracts, and Evidence semantics.

51/ 100
Use with care

Useful, but reliability, evidence or controls still have material gaps.

See how it was scored ↓
Works as-is in
Codex · Claude Code
Stars
★ 71k
Last updated
today
License
MIT
reverse-engineeringbinary-analysisghidrahopper
+4mcpstatic-analysisdecompilercli

What does this skill do, and when should you use it?

rea-tool-design is one of the skills bundled in the REA (Reverse Engineer Anything) repository. Its job is tool design for REA itself: defining tool boundaries, input/result contracts, provider ownership, and Evidence semantics. It does not analyze binaries or apps; it is a design-and-convention skill aimed at contributors and maintainers. The repository is installed via npx rea-agents setup, which registers the MCP server, and is MIT licensed. If you only want to reverse engineer an app, this skill is not the entry point; if you want to add or modify REA tools, it is the required specification.

  • Reads the repo's tool-design guide (docs/tool-design.md) for tool boundaries, contract semantics, provider ownership, and discoverability
  • Inspects the current contract and the nearest existing tool relevant to the analyst question before designing
  • For a design request, returns the proposed boundary, input/result shape, Evidence semantics, nearest alternative, and verification approach
  • Implements designs when requested, preserving user scope and existing authorization
  • Points implementation/verification work at the testing guide and CONTRIBUTING.md for generated-file ownership
Good fit
  • A contributor adding a new tool to REA who must settle the tool boundary and contract shape before writing code
  • A maintainer changing an existing tool's input/result shape who needs to keep Evidence semantics consistent
  • A reviewer checking whether a proposed tool duplicates the nearest existing tool in the catalog
  • A developer implementing or verifying a tool change who needs the correct consumer/provider testing lanes from the testing guide
Not a fit
  • Regular users who just want to reverse engineer an app or binary — this skill provides no analysis capability; analysis comes from REA's MCP server tools
  • External users who won't read or modify the REA repository — all content references in-repo docs, making it meaningless in isolation

How do you install this skill?

Before you use it
  • This skill is design guidance only; its real value depends on unreviewed docs/tool-design.md and docs/testing.md, which users should confirm exist and match the current version.
  • Reverse engineering carries legal and authorization risks; the skill requires preserving existing authorization, and users remain responsible for lawful targets.
  • Native analysis depends on Hopper/Ghidra/IDA, whose download and licensing reachability may be limited in some regions including mainland China.
  • The publisher is unverified by the FollowSkills registry; maintenance responsibility and update path cannot be independently confirmed.
Before you start
Your agent needs
  • Shell / CLI
  • Local filesystem
Install first
  • Node.js 22.x (>=22.19) / 24.x / 26+
  • npm
  • rea-agents CLI (npx rea-agents setup)

The README documents installation of the whole REA collection only; no standalone install command for this skill is documented:
Any agent with local MCP support (Claude Code, Codex, Cursor, Gemini CLI, etc.)

npx rea-agents setup

npm global CLI

npm install --global rea-agents
rea --help

How do you use this skill?

Try saying

Once installed, send your agent any of these to trigger it:

  • Design a new crash-log analysis tool for REA, giving the tool boundary, input/result shape, and Evidence semantics
  • Check the existing analyze-javascript-application contract and whether the field I want to add duplicates the nearest tool
  • I'm changing a tool's result shape — per the tool-design guide, what Evidence semantics and verification approach apply?

The skill ships as .agents/skills/rea-tool-design/SKILL.md and is installed with the collection via setup. Trigger it by asking your agent a tool-design question. The flow: consult the tool-design guide → inspect the current contract and nearest existing tool (source, docs, and live catalogs may describe different versions) → produce a design covering boundary, input/result shape, Evidence semantics, nearest alternative, and verification approach → implement only when requested, preserving the user's scope and existing authorization. For implementation or verification, consult the testing guide and CONTRIBUTING.md; read other provider/workflow guides only as needed.

What are this skill's strengths and limitations?

Pros
  • Gives the REA tool ecosystem an explicit contract and Evidence-semantics standard, lowering the contribution barrier
  • Requires checking the nearest existing tool first, preventing duplicate designs
  • Design output includes a verification approach; design and implementation are kept separate, respecting user scope and authorization
Limitations
  • Produces no analysis results itself; its value is entirely dependent on the REA repository and its docs existing
  • Heavy use of relative-path links to in-repo docs means standalone installation breaks the reference chain
  • The README does not state the skill's version or alignment with REA releases, so docs and code may be out of sync

How does this skill compare with similar options?

Side by side with related skills; every score comes from the same FSRS standard.

Skill FS score Stars Last updated License
REA Tool Design Skill this page 51 · Use with care ★ 71k today MIT
REA: Reverse Engineer Anything 59 · Recommended ★ 71k today MIT
Pulser — SKILL.md Linter 50 · Use with care ★ 18 3mo ago MIT
BlockWatch 67 · Recommended ★ 29 3d ago MIT
CodeRabbit Review Skill 53 · Use with care ★ 35 2mo ago Unlicense

The source offers no direct competitor to compare against; the other skills in the REA collection handle actual reverse-engineering work, while this one only defines tool-design conventions.

How did FollowSkills review this skill?

FollowSkills review · FSRS-2.0
Use with care
51/ 100 5-point scale 2.6 / 5
1Trust14 / 25 · 2.8/5

The skill contains only design guidance: no file writes, network access, or destructive operations, and it explicitly instructs preserving user scope and existing authorization. However, its substance depends entirely on repository docs (tool-design.md, testing.md) not shown in this review, so permission boundaries and rollback cannot be independently verified; scored accordingly.

2Reliability9 / 20 · 2.3/5

Instructions are self-consistent and give a clear deliverable contract (boundary, input/result shape, Evidence semantics, nearest alternative, verification). Key paths point to unreviewed guides whose existence and consistency could not be statically confirmed, and failure feedback on abnormal input is unverifiable; capped at 10 for static review.

3Adaptability8 / 15 · 2.7/5

The scenario is clear (designing or changing REA investigation tools, CLI/MCP contracts, Evidence semantics), and trigger semantics match the name. Non-fit boundaries, example inputs/outputs, and environment requirements are undeclared; reachability of the upstream toolchain (Hopper/Ghidra/IDA) from mainland-China networks is unaddressed, hence the deduction.

4Convention10 / 15 · 3.3/5

The skill is generated by scripts/generate-skill-metadata.mjs with CI metadata checks, MIT license is clear, and repository governance (CI, tests, contributing) is visible. The skill file itself lacks versioning, changelog, examples, and known-limitation disclosure, and maintenance responsibility rests on an unverified publisher; scored accordingly.

5Effectiveness6 / 15 · 2.0/5

The design-request checklist is directly reusable and offers some marginal value, but output quality depends on unreviewed guide content and statically unverifiable claims; the 7-point static ceiling applies.

6Verifiability4 / 10 · 2.0/5

The repository contains real CI workflows and extensive tests, but none covering this skill file's key paths. Claims about contract semantics and verification approach cannot be independently reproduced in a static read; scored accordingly.

1 2 3 4 5 6

Open a dimension to read why it scored that way

Reviewed Oct 10, 2026 Reviewed revision 26038912f6ce Review evidence[1][2][3][4][5][6][7][8][9]

Evidence confidence:Low — Mostly static review, author material or a limited demo; useful for discovery, not high-risk decisions.

See the full review method →

FAQ

Can this skill reverse engineer an app for me?
No. It only defines REA's tool-design conventions; actual analysis is done by REA's MCP server tools, which require npx rea-agents setup first.
Is it useful to install this skill standalone?
Limited value. SKILL.md references docs/tool-design.md, docs/testing.md, and CONTRIBUTING.md via relative paths, which don't resolve outside the full repository.
What does it cost or what permissions does it need?
The repository is MIT licensed with no usage fee; the skill emphasizes preserving the user's existing authorization scope when implementing, but documents no additional permission requirements.

More skills from this repository

All from morluto/rea

Related skills