mrkeyoor.com_
Tue 06 Oct 15:54 UTC
Dev Toolsevaluationupdated 06 Oct 2026

rea review

REA gives coding agents a local MCP and command-line interface for inspecting native binaries, JavaScript and Electron apps, .NET assemblies, APKs, and websites. It helps an agent trace how a feature works and preserve the evidence behind its explanation, instead of treating decompiler output as original source.

Verdict

Our REA run passed 3,372 of 3,374 tests with 2 skipped, but npm audit still reported 3 high-severity vulnerabilities, so the engineering evidence is strong without giving the dependency tree a free pass. Use it when an agent needs to move across several reverse-engineering domains and you have a human checking the evidence. Choose a narrower tool when one binary format, a small context budget, or a self-contained install matters more.

We ran it

Lab card: what happened when we ran reaScreenshot of rea (github.com/morluto/rea)
Install✓ · 11s278 packages · 266 MB
Build✓ · 23s
Tests✓ · 341s3372 passed · 0 failed · 2 skipped of 3374 (vitest)
Known vulns30 critical · 3 high · 0 moderate · 0 low (npm audit)
Repo1502 files~235,008 lines of source · 16.9 MB · 6 CI workflows · tests dir

Answers from our run

Does rea build from source?

Dependencies installed in 11 seconds (278 packages), and the build succeeded in 23 seconds. We cloned commit 00eb03d into a clean Debian container with 3 CPUs and no project-specific setup.

Do rea's tests pass?

Yes: 3372 of 3374 passed when we ran the project's own test command (vitest). Some failures need services or credentials a bare container does not have.

Does rea have known vulnerabilities in its dependencies?

npm audit flagged 3 known advisories in the dependency tree at the time of our run.

Who should not use rea?

Anyone expecting a self-contained decompiler: native work needs a separate Hopper license or an existing Ghidra 12.1.4 and 64-bit JDK 21 installation.

What are the alternatives to rea?

Ghidra, radare2, capa. Our REA run passed 3,372 of 3,374 tests with 2 skipped, but npm audit still reported 3 high-severity vulnerabilities, so the engineering evidence is strong without giving the dependency tree a free pass.

Setup3/5Fast npm setup, but useful providers need separate tools
Docs5/5Detailed prerequisites, boundaries, evidence rules, and examples
Community4/57,293 stars and active issues and PRs on October 6, 2026
Maturity4/53,372 tests passed, though large-target limits remain open

Who it’s for

Developers who want Claude Code, Codex, Cursor, or another MCP client to investigate software they are allowed to inspect.
Reverse engineers who want CLI and agent workflows to share evidence, sessions, and comparison tools.
Teams working across native code, Electron, browser behavior, APKs, and .NET without building a separate agent adapter for each tool.
Security researchers who will review the agent's evidence and unresolved findings before acting on a conclusion.

Who it’s NOT for

Anyone expecting a self-contained decompiler: native work needs a separate Hopper license or an existing Ghidra 12.1.4 and 64-bit JDK 21 installation.
Teams with tight agent-context budgets: open issue 723 measured 117 MCP tools and 1,949,695 bytes of complete tool definitions.
Analysts processing large JavaScript bundles without a fallback: issue 623 reproduces an Invalid string length failure on REA's own 719-file compiled directory.
Users who install only the published agent skill and expect working MCP tools: issue 737 says the skill alone does not register the server.
Anyone who needs recovered original source code or proof of runtime causality: the README explicitly limits decompilation and correlation claims.

Setup reality

Our fresh Node 22 sandbox installed commit 00eb03d in 11 seconds, adding 278 packages and using 266 MB. The build passed in 23 seconds. Vitest finished in 341 seconds with 3,372 passed, 0 failed, and 2 skipped out of 3,374. npm audit found 3 high-severity vulnerabilities.

Useful analysis needs more than the npm package. Native targets require Hopper or Ghidra 12.1.4 with a 64-bit JDK 21. APK analysis needs a supplied JADX JAR and Java. MCP clients need registration and a restart after setup.

REA supports macOS 12 or newer plus selected Linux distributions. Windows Ghidra support is experimental and limited to read-only x86-64 PE files on local NTFS. Some browser and runtime work needs an existing Chrome-family or Inspector target, while Hopper setup may require system authorization.

REA connects 117 agent tools to several kinds of software

REA is an MCP server and CLI for investigations that normally spill across unrelated programs. It can inspect native binaries through Hopper or Ghidra, map JavaScript and Electron applications without executing their modules, read .NET metadata and CIL, inspect APKs through JADX, observe a selected browser, and capture declared process behavior. The same application workflows sit behind the terminal and MCP interfaces, so an agent can retain evidence while moving between questions.

That breadth is the reason to consider it. A developer can start with a string seen in an app, follow references into code, compare artifacts, and give the result back to a coding agent. REA records artifact identity, provider details, locations, confidence, limitations, and unknowns. Its README is careful about the boundary: pseudocode is not recovered original source, and a correlation between static and runtime findings does not prove causality.

The 11-second install does not include the analysis engines

The npm path is short, but a working investigation depends on the target. REA requires supported Node 22, 24, or 26 releases and runs on macOS 12 or newer plus named Linux distributions. Native analysis needs separate software. Hopper has its own license and demo limits. Ghidra support requires version 12.1.4 and a 64-bit JDK 21, supplied by you. Static APK work also expects Java and a headless JADX JAR.

Setup can register supported agents, back up existing configuration, and show changes before applying them. Restart the client afterward. Open issue 737 catches an easy mistake: installing the reverse-engineer-anything skill by itself provides instructions, but it does not register REA's MCP server. Issue 726 also documents how the broad doctor command can complain about unrelated optional providers even when a JavaScript task already works. Provider-scoped checks exist, though the quick start does not yet explain that path well.

What happened when we ran it

Our sandbox installed commit 00eb03d in 11 seconds. npm added 278 packages and the installed tree occupied 266 MB. The repository itself contained 1,502 files, about 235,008 lines of source, and a 16.9 MB checkout. The build completed successfully in 23 seconds. We found 6 CI workflow files and a tests directory, but no Dockerfile.

Vitest ran for 341 seconds and reported 3,372 passed, 0 failed, and 2 skipped out of 3,374 tests. That is a serious test corpus, and it passed under 3 CPUs, 8 GB of RAM, Node 22, no secrets, and no elevated privileges. npm audit still found 3 known high-severity vulnerabilities, with no critical, moderate, or low findings. Those advisories deserve review before REA is placed beside sensitive proprietary targets.

The sandbox result covers installation, compilation, tests, and the dependency audit. It does not test Hopper, Ghidra, JADX, a real MCP client, browser capture, decompilation quality, or reconstructed code. Treat the green suite as evidence that this commit builds cleanly, not as proof that every external provider is ready on your workstation.

Complete evidence can consume more context than the target

REA's insistence on complete evidence has a measurable cost. Open issue 723 reports 117 discovered MCP tools. Their complete definitions, including output schemas, occupied 1,949,695 bytes in that evaluation. Names, descriptions, and input schemas alone used 699,835 bytes. For a three-file JavaScript fixture containing 422 text bytes, MCP output reached 759,454 bytes because structured results and evidence repeat information for compatibility.

This is not a cosmetic complaint when an agent pays for every token it receives. The issue estimates 167,799 proxy tokens for the input-facing projection, while warning that this is not every host's actual tokenizer or context cost. The team is discussing concise summaries and reduced repetition without dropping provenance or unknowns. Until that changes, test discovery and one representative result in the exact MCP client you plan to use.

Large JavaScript targets still hit a hard string limit

Open issue 623 gives the clearest reason to keep another tool nearby. REA 3.2.1 failed while analyzing its own compiled directory, a target of 719 JavaScript files and about 5.7 MB of source. The public error only said reason: io; the underlying exception was RangeError: Invalid string length while canonicalizing a whole semantic graph for hashing. The reporter also found a second full-result failure in JSON formatting.

That bug is more relevant than a vague warning about scale. REA is meant to inspect applications, and compiled Electron or JavaScript packages can be much larger than 719 files. Filtering the output helped one formatter path in the report, but the analysis failure happened earlier. Before adopting REA for a large bundle, run the largest real target through the same version and preserve a CLI fallback for narrower queries.

Active development brings fixes and moving edges

GitHub showed 7,293 stars, MIT licensing, and 71 combined open issues and pull requests on October 6, 2026. The repository was pushed that day, one day after release 4.0.1. Current activity includes Android integration, firmware work, browser metadata fixes, documentation gaps, and an open design question about how investigations should retain evidence after a target closes. This is active maintenance, with interfaces still being refined.

REA makes the most sense when breadth and auditable agent work are worth the provider setup and context load. Our passing 3,372-test run gives it more credibility than a polished MCP demo. The 3 high-severity audit findings, 1.95 MB tool catalog, and reproducible large-target failure set the conditions for adoption: pin the version, inspect dependencies, test your biggest artifact, and keep a human responsible for the conclusion.

Alternatives

ProjectWhat it isPick it when
Ghidra gh↗A full reverse-engineering suite with disassembly, decompilation, scripting, and collaborative analysis.pick this instead when a human-led desktop workflow matters more than an agent-facing MCP layer.
radare2 gh↗A scriptable command-line framework for binary inspection, debugging, and patching.pick this instead when you want a mature terminal toolkit and will assemble your own agent integration.
capaA focused tool that identifies capabilities in executable files from maintained rules.pick this instead when malware capability detection is the job and an open-ended investigation session is unnecessary.

What people are saying

  1. [github-trending] morluto/rea

Sources

  1. REA repository
  2. REA README
  3. REA 4.0.1 release
  4. Large JavaScript target failure issue
  5. MCP discovery and result-size issue
  6. Skill bootstrap issue

More dev tools reviews

kubescape · amass · grokbot-field-notes · abide · dsh-echocat-skill-panel · Compositor · the whole board →