What does this skill do, and when should you use it?
REA (Reverse Engineer Anything) is an MCP server plus a companion skill that lets a coding agent inspect native binaries, JavaScript/Electron apps, .NET assemblies, Android APKs, firmware, websites, and saved network captures. Analysis runs locally, and every conclusion carries evidence, evidence type (observation/inference/unknown), and coverage limits. Deep native analysis can reuse an existing Hopper, Ghidra, or IDA installation; static JavaScript and .NET analysis need no native engine at all. The skill file itself only supplies investigation instructions — it does not register the MCP server or install engines; the actual tools ship in the `rea-agents` package.
- Binds binary/archive targets via
open_binaryand produces pseudocode, assembly, symbols, and call references throughanalyze_function,binary_overview, and related tools - Recovers modules, imports, routes, and IPC boundaries from Electron/ASAR apps with
analyze_javascript_application, tracing a feature withtrace_application_feature - Extracts APK manifest declarations, classes, and decompiled methods with
inspect_android_package; checks .NET metadata and CIL withinspect_managed_artifact - Analyzes firmware regions with
inspect_firmware_regions/extract_firmware(Binwalk/Unblob) and handles offline ELF layout, Linux crash dumps, and EVM bytecode viainspect_binary_layout,inspect_recorded_crash,inspect_evm_interface - Passively observes an already-open user-owned browser or Electron runtime (
list_browser_targets,list_electron_targets) and inspects HAR/mitmproxy captures offline - Maintains an evidence ledger: each conclusion links Evidence IDs, confidence, and remaining unknowns, exportable via
export_evidence_bundle
- A developer who wants a feature from another app in their own product: have the agent explain how it works with evidence, then build a similar version with normal coding tools
- A CTF player or security researcher who needs to decompile native binaries, check ELF static mitigations, or read Linux core dumps
- A maintainer comparing two packaged versions of the same app across modules, imports, or build differences
- Someone analyzing an Android APK: manifest declarations, class structure, method references, or decoded resources and string tables
- A researcher of firmware images or EVM smart-contract bytecode: identify regions, extract images, or decode dispatch selectors and arguments
- An engineer debugging an Electron app: trace clipboard, IPC, or other features from renderer through preload into the main process
- Ordinary architecture analysis of a complete source repository — SKILL.md explicitly says to use normal repository tools and skip REA in that case
- Users unwilling to install Node.js 22+ plus per-target tooling (Hopper/Ghidra/IDA, JADX, pwntools, Binwalk, etc.)
- Firmware, EVM bytecode, offline ELF, and crash-dump analysis on non-Linux-x64 hosts — the docs require caller-supplied tools on Linux x64
How do you install this skill?
- SKILL.md instructs npx -y rea-agents@latest, an unpinned remote-code fetch; pin a reviewed version in constrained or security-sensitive environments.
- Runtime-observation operations (observe_native_calls, browser/Electron attach) actually run or touch target processes with the current user's permissions; use only on authorized targets.
- REA imposes no per-call approval gating itself and relies on client policy; configure client-side approvals explicitly for unattended runs.
- Documentation and dependencies are English-only and rely on overseas npm/GitHub/rea.tools resources; mainland-China network reachability may be limited.
- Deep native/Android/firmware analysis requires bring-your-own Hopper/Ghidra/IDA/JADX engines; availability varies by host and by released npm version versus repository main.
- The skill supplies instructions only and does not register the MCP server; run rea-agents setup and restart your agent first.
- Shell / CLI
- Network access
- Local filesystem
- MCP Server
Node.js 22.x (>=22.19) / 24.x / 26+ and npmrea-agents MCP server (npx rea-agents setup)Optional: Hopper, Ghidra, or IDA for native analysisOptional: pwntools, JADX + JDK, Binwalk/Unblob, adb, Apktool depending on target
Installation has two layers: the skill file (available from the repo's .agents/skills/ path or via skills.sh) only supplies instructions; the tools themselves are registered through the npm package rea-agents.
Claude Code / Codex / Cursor / Gemini CLI / Grok Build and other supported agents
npx rea-agents setupChoose your agents, review the proposed changes, approve them, and restart your agent.
Terminal CLI (global install)
npm install --global rea-agents
rea --helpOne-off commands (no install)
npx -y rea-agents@latest --helpUpdate an installed CLI with rea update; npx users refresh registration and the skill with npx rea-agents@latest setup.
How do you use this skill?
Once installed, send your agent any of these to trigger it:
- Understand how search works in the Notes app, show me the evidence, and build a similar feature for my project.
- Analyze /absolute/path/to/app.asar — list the modules and IPC boundaries of this Electron app with evidence.
- Decompile the key functions in this native binary, explain the sound-pan calculation like the DX-Ball showcase, and give me a compilable C version.
- Compare these two versions of the APK's manifest declarations and method references, and flag behavioral differences plus remaining unknowns.
The skill is triggered by the conversation: when a claim depends on a shipped binary/package, decompilation, passive runtime evidence, or version comparison, the agent routes to the first tool by target type (native targets via open_binary, APKs via inspect_android_package, JavaScript/ASAR via analyze_javascript_application, and so on). Start with the default summary result and use inline Evidence and graph context; for large JavaScript or ELF results request "detail": "summary" and page through with inspect_analysis_view, never repeating identical analyses. Every conclusion must distinguish observations, inferences, and unknowns, citing Evidence IDs. Native analysis requires a configured provider (Hopper/Ghidra/IDA; IDA registers via mrexodia/ida-pro-mcp). Runtime observation executes the declared target under your user permissions; static analysis reads files only. Close an opened native session with close_binary when done.
What are this skill's strengths and limitations?
- Broad coverage: one MCP handles native binaries, JavaScript/Electron, .NET, APKs, firmware, browser, captures, and process capture
- Local analysis: targets are never uploaded, and results carry evidence, limitations, and unknowns so conclusions are auditable
- Reuses existing engines: Hopper, Ghidra, or IDA can serve as native providers; static JavaScript/.NET analysis needs no engine
- Simple install/update: one `npx rea-agents setup` registers everything with backups of existing config; `rea update` keeps it current
- Requires Node.js 22.x (>=22.19), 24.x, or 26+, and deep native analysis additionally needs an installed Hopper, Ghidra, or IDA
- Several target types depend on caller-supplied tools (pwntools, JADX+JDK, Binwalk/Unblob, adb, Apktool), some limited to Linux x64
- Installing the skill only supplies instructions — it does not register the MCP server or install engines; without setup the tools are unavailable
- A skill from repository main may describe capabilities absent from the released npm version, creating version drift
- Runtime observation executes the declared target; users are responsible for authorization and legal compliance, with no warranty under MIT
How does this skill compare with similar options?
Side by side with related skills; every score comes from the same FSRS standard.
| Skill | FS score | Stars | Last updated | License |
|---|---|---|---|---|
| REA: Reverse Engineer Anything this page | 59 · Recommended | ★ 71k | today | MIT |
| REA Tool Design Skill | 51 · Use with care | ★ 71k | today | MIT |
| Open Code Review — AI Code Quality Gate | 46 · Use with care | ★ 40 | 5mo ago | NOASSERTION |
| Engram Persistent Memory Protocol | 68 · Recommended | ★ 7.1k | 4d ago | MIT |
| LeanCTX — Local Context Intelligence Layer | 61 · Recommended | ★ 3.9k | 3d ago | Apache-2.0 |
REA itself integrates Hopper, Ghidra, and IDA as selectable native-analysis providers, and reuses mrexodia/ida-pro-mcp for IDA installation and registration; it is not a replacement for those tools but a bridge from their output into an agent workflow. For pure static work it also wraps upstream tools such as pwntools (ELF layout), JADX (APKs), and Binwalk/Unblob (firmware).
How did FollowSkills review this skill?
Evidence shows strong least-privilege discipline: local analysis by default, passive observation without executing targets, deliberate credential exclusion in HAR captures, read-only setup plans with backups before changes, refusal to install unrelated software, and mandated observation/inference/unknown separation. Deducted for: npx -y rea-agents@latest pulling an unpinned version, runtime capture that actually runs targets with user permissions (observe_native_calls), no per-call approval gating inside REA (deferred to client policy), and unverified publisher identity.
Instructions are self-consistent and layered, with detailed failure-recovery tables, partial-result recovery, truncation handling, and anti-repetition rules. Deducted for: static review cannot reproduce key paths; the skill itself warns of drift between repository main and released npm versions; JADX and other bring-your-own dependencies are version-sensitive; test coverage of the skill's key paths could not be verified, so the static ceiling of 10 applies.
Trigger conditions are explicit (use when a claim depends on shipped binaries, decompilation or runtime evidence; explicitly skip ordinary source-repo analysis), with a clear target routing table and non-fit boundaries (e.g., NativeAOT is not source recovery). Deducted for: English-only documentation with no Chinese support, and core function depends on npm/GitHub/rea.tools and overseas services, with reachability risk from mainland-China networks unaddressed in the skill.
SKILL.md shows good progressive disclosure (router main file plus topic references plus upstream docs), metadata version "37", MIT license, SECURITY.md, a clear maintenance/update path (rea update, setup), and explicit legal disclaimers. Deducted for: no changelog at the skill level, unexplained version numbering semantics, and unversioned anchors for external documentation URLs.
The target-evidence-conclusion workflow has clear marginal value for reverse-engineering tasks, and showcases (DX-Ball, Notion, TH04) describe usable output forms. Deducted for: static review cannot verify outputs are directly usable; real value is contingent on REA MCP server and external engines (Hopper/Ghidra/IDA/JADX) being available, making cost/benefit sensitive to those prerequisites.
The skill mandates distinguishing observation/inference/unknown, citing Evidence IDs, and preserving limitations and coverage; the repository includes a CI workflow, extensive verify/test scripts, and a SECURITY.md boundary statement. Deducted for: static review executed nothing and independently reproduced nothing; showcases are author-supplied demonstrations not independently corroborated within this evidence.
Open a dimension to read why it scored that way
Evidence confidence:Low — Mostly static review, author material or a limited demo; useful for discovery, not high-risk decisions.
See the full review method →