Dev & Engineering

REA: Reverse Engineer Anything

Connect Claude Code and other agents to the REA MCP server to explain app features without source code, decompile code, and compare versions — down to the binary level.

59/ 100
Recommended

Generally reliable with disclosed limitations; trial as directed and keep a rollback path.

See how it was scored ↓
Works as-is in
ChatGPT · Codex · Claude Code
Stars
★ 71k
Last updated
today
License
MIT
reverse-engineeringbinary-analysisdecompilerghidra
+6idamcp-serverandroid-apkelectron-appsfirmware-analysisstatic-analysis

What does this skill do, and when should you use it?

REA (Reverse Engineer Anything) is an MCP server plus a companion skill that lets a coding agent inspect native binaries, JavaScript/Electron apps, .NET assemblies, Android APKs, firmware, websites, and saved network captures. Analysis runs locally, and every conclusion carries evidence, evidence type (observation/inference/unknown), and coverage limits. Deep native analysis can reuse an existing Hopper, Ghidra, or IDA installation; static JavaScript and .NET analysis need no native engine at all. The skill file itself only supplies investigation instructions — it does not register the MCP server or install engines; the actual tools ship in the `rea-agents` package.

  • Binds binary/archive targets via open_binary and produces pseudocode, assembly, symbols, and call references through analyze_function, binary_overview, and related tools
  • Recovers modules, imports, routes, and IPC boundaries from Electron/ASAR apps with analyze_javascript_application, tracing a feature with trace_application_feature
  • Extracts APK manifest declarations, classes, and decompiled methods with inspect_android_package; checks .NET metadata and CIL with inspect_managed_artifact
  • Analyzes firmware regions with inspect_firmware_regions/extract_firmware (Binwalk/Unblob) and handles offline ELF layout, Linux crash dumps, and EVM bytecode via inspect_binary_layout, inspect_recorded_crash, inspect_evm_interface
  • Passively observes an already-open user-owned browser or Electron runtime (list_browser_targets, list_electron_targets) and inspects HAR/mitmproxy captures offline
  • Maintains an evidence ledger: each conclusion links Evidence IDs, confidence, and remaining unknowns, exportable via export_evidence_bundle
Good fit
  • A developer who wants a feature from another app in their own product: have the agent explain how it works with evidence, then build a similar version with normal coding tools
  • A CTF player or security researcher who needs to decompile native binaries, check ELF static mitigations, or read Linux core dumps
  • A maintainer comparing two packaged versions of the same app across modules, imports, or build differences
  • Someone analyzing an Android APK: manifest declarations, class structure, method references, or decoded resources and string tables
  • A researcher of firmware images or EVM smart-contract bytecode: identify regions, extract images, or decode dispatch selectors and arguments
  • An engineer debugging an Electron app: trace clipboard, IPC, or other features from renderer through preload into the main process
Not a fit
  • Ordinary architecture analysis of a complete source repository — SKILL.md explicitly says to use normal repository tools and skip REA in that case
  • Users unwilling to install Node.js 22+ plus per-target tooling (Hopper/Ghidra/IDA, JADX, pwntools, Binwalk, etc.)
  • Firmware, EVM bytecode, offline ELF, and crash-dump analysis on non-Linux-x64 hosts — the docs require caller-supplied tools on Linux x64

How do you install this skill?

Before you use it
  • SKILL.md instructs npx -y rea-agents@latest, an unpinned remote-code fetch; pin a reviewed version in constrained or security-sensitive environments.
  • Runtime-observation operations (observe_native_calls, browser/Electron attach) actually run or touch target processes with the current user's permissions; use only on authorized targets.
  • REA imposes no per-call approval gating itself and relies on client policy; configure client-side approvals explicitly for unattended runs.
  • Documentation and dependencies are English-only and rely on overseas npm/GitHub/rea.tools resources; mainland-China network reachability may be limited.
  • Deep native/Android/firmware analysis requires bring-your-own Hopper/Ghidra/IDA/JADX engines; availability varies by host and by released npm version versus repository main.
  • The skill supplies instructions only and does not register the MCP server; run rea-agents setup and restart your agent first.
Before you start
Your agent needs
  • Shell / CLI
  • Network access
  • Local filesystem
  • MCP Server
Install first
  • Node.js 22.x (>=22.19) / 24.x / 26+ and npm
  • rea-agents MCP server (npx rea-agents setup)
  • Optional: Hopper, Ghidra, or IDA for native analysis
  • Optional: pwntools, JADX + JDK, Binwalk/Unblob, adb, Apktool depending on target

Installation has two layers: the skill file (available from the repo's .agents/skills/ path or via skills.sh) only supplies instructions; the tools themselves are registered through the npm package rea-agents.

Claude Code / Codex / Cursor / Gemini CLI / Grok Build and other supported agents

npx rea-agents setup

Choose your agents, review the proposed changes, approve them, and restart your agent.

Terminal CLI (global install)

npm install --global rea-agents
rea --help

One-off commands (no install)

npx -y rea-agents@latest --help

Update an installed CLI with rea update; npx users refresh registration and the skill with npx rea-agents@latest setup.

How do you use this skill?

Try saying

Once installed, send your agent any of these to trigger it:

  • Understand how search works in the Notes app, show me the evidence, and build a similar feature for my project.
  • Analyze /absolute/path/to/app.asar — list the modules and IPC boundaries of this Electron app with evidence.
  • Decompile the key functions in this native binary, explain the sound-pan calculation like the DX-Ball showcase, and give me a compilable C version.
  • Compare these two versions of the APK's manifest declarations and method references, and flag behavioral differences plus remaining unknowns.

The skill is triggered by the conversation: when a claim depends on a shipped binary/package, decompilation, passive runtime evidence, or version comparison, the agent routes to the first tool by target type (native targets via open_binary, APKs via inspect_android_package, JavaScript/ASAR via analyze_javascript_application, and so on). Start with the default summary result and use inline Evidence and graph context; for large JavaScript or ELF results request "detail": "summary" and page through with inspect_analysis_view, never repeating identical analyses. Every conclusion must distinguish observations, inferences, and unknowns, citing Evidence IDs. Native analysis requires a configured provider (Hopper/Ghidra/IDA; IDA registers via mrexodia/ida-pro-mcp). Runtime observation executes the declared target under your user permissions; static analysis reads files only. Close an opened native session with close_binary when done.

What are this skill's strengths and limitations?

Pros
  • Broad coverage: one MCP handles native binaries, JavaScript/Electron, .NET, APKs, firmware, browser, captures, and process capture
  • Local analysis: targets are never uploaded, and results carry evidence, limitations, and unknowns so conclusions are auditable
  • Reuses existing engines: Hopper, Ghidra, or IDA can serve as native providers; static JavaScript/.NET analysis needs no engine
  • Simple install/update: one `npx rea-agents setup` registers everything with backups of existing config; `rea update` keeps it current
Limitations
  • Requires Node.js 22.x (>=22.19), 24.x, or 26+, and deep native analysis additionally needs an installed Hopper, Ghidra, or IDA
  • Several target types depend on caller-supplied tools (pwntools, JADX+JDK, Binwalk/Unblob, adb, Apktool), some limited to Linux x64
  • Installing the skill only supplies instructions — it does not register the MCP server or install engines; without setup the tools are unavailable
  • A skill from repository main may describe capabilities absent from the released npm version, creating version drift
  • Runtime observation executes the declared target; users are responsible for authorization and legal compliance, with no warranty under MIT

How does this skill compare with similar options?

Side by side with related skills; every score comes from the same FSRS standard.

Skill FS score Stars Last updated License
REA: Reverse Engineer Anything this page 59 · Recommended ★ 71k today MIT
REA Tool Design Skill 51 · Use with care ★ 71k today MIT
Open Code Review — AI Code Quality Gate 46 · Use with care ★ 40 5mo ago NOASSERTION
Engram Persistent Memory Protocol 68 · Recommended ★ 7.1k 4d ago MIT
LeanCTX — Local Context Intelligence Layer 61 · Recommended ★ 3.9k 3d ago Apache-2.0

REA itself integrates Hopper, Ghidra, and IDA as selectable native-analysis providers, and reuses mrexodia/ida-pro-mcp for IDA installation and registration; it is not a replacement for those tools but a bridge from their output into an agent workflow. For pure static work it also wraps upstream tools such as pwntools (ELF layout), JADX (APKs), and Binwalk/Unblob (firmware).

How did FollowSkills review this skill?

FollowSkills review · FSRS-2.0
Recommended
59/ 100 5-point scale 3.0 / 5
1Trust18 / 25 · 3.6/5

Evidence shows strong least-privilege discipline: local analysis by default, passive observation without executing targets, deliberate credential exclusion in HAR captures, read-only setup plans with backups before changes, refusal to install unrelated software, and mandated observation/inference/unknown separation. Deducted for: npx -y rea-agents@latest pulling an unpinned version, runtime capture that actually runs targets with user permissions (observe_native_calls), no per-call approval gating inside REA (deferred to client policy), and unverified publisher identity.

2Reliability10 / 20 · 2.5/5

Instructions are self-consistent and layered, with detailed failure-recovery tables, partial-result recovery, truncation handling, and anti-repetition rules. Deducted for: static review cannot reproduce key paths; the skill itself warns of drift between repository main and released npm versions; JADX and other bring-your-own dependencies are version-sensitive; test coverage of the skill's key paths could not be verified, so the static ceiling of 10 applies.

3Adaptability9 / 15 · 3.0/5

Trigger conditions are explicit (use when a claim depends on shipped binaries, decompilation or runtime evidence; explicitly skip ordinary source-repo analysis), with a clear target routing table and non-fit boundaries (e.g., NativeAOT is not source recovery). Deducted for: English-only documentation with no Chinese support, and core function depends on npm/GitHub/rea.tools and overseas services, with reachability risk from mainland-China networks unaddressed in the skill.

4Convention11 / 15 · 3.7/5

SKILL.md shows good progressive disclosure (router main file plus topic references plus upstream docs), metadata version "37", MIT license, SECURITY.md, a clear maintenance/update path (rea update, setup), and explicit legal disclaimers. Deducted for: no changelog at the skill level, unexplained version numbering semantics, and unversioned anchors for external documentation URLs.

5Effectiveness6 / 15 · 2.0/5

The target-evidence-conclusion workflow has clear marginal value for reverse-engineering tasks, and showcases (DX-Ball, Notion, TH04) describe usable output forms. Deducted for: static review cannot verify outputs are directly usable; real value is contingent on REA MCP server and external engines (Hopper/Ghidra/IDA/JADX) being available, making cost/benefit sensitive to those prerequisites.

6Verifiability5 / 10 · 2.5/5

The skill mandates distinguishing observation/inference/unknown, citing Evidence IDs, and preserving limitations and coverage; the repository includes a CI workflow, extensive verify/test scripts, and a SECURITY.md boundary statement. Deducted for: static review executed nothing and independently reproduced nothing; showcases are author-supplied demonstrations not independently corroborated within this evidence.

1 2 3 4 5 6

Open a dimension to read why it scored that way

Reviewed Oct 10, 2026 Reviewed revision 26038912f6ce Review evidence[1][2][3][4][5][6][7][8][9][10][11][12]

Evidence confidence:Low — Mostly static review, author material or a limited demo; useful for discovery, not high-risk decisions.

See the full review method →

FAQ

Does using REA cost money or require a license?
REA is MIT-licensed open-source software and the npm package is free. If you pick Hopper as your native engine, a first-run dialog on macOS may ask you to choose demo mode or activate your Hopper license; Ghidra and IDA use your existing installations.
Can I use it without Hopper, Ghidra, or IDA?
Yes. Static JavaScript/Electron and .NET analysis need no native engine; only native pseudocode/assembly analysis requires one of the three.
Does REA upload my app?
No — REA analyzes targets locally. Your agent receives the tool results, and its model provider has its own data policy.
What if I hit a bug?
Update first: `rea update` (CLI) or `npx rea-agents@latest setup` (agent registration), restart your agent, and retry. If it persists, open an issue with your REA version, target type, steps to reproduce, and error output.

More skills from this repository

All from morluto/rea

Related skills