Reverse engineering usually means an operator picks a tool, learns its API, and moves evidence between programs by hand. REA, an open-source toolkit released on GitHub in April 2026, gives that job to an AI agent instead: hand it an application — source code optional — and it investigates a feature, explains how it works, shows the evidence, and builds an adapted version for your stack. The repository sits at 2,862 stars and the rea-agents npm package at 2.5.0.
The investigation model
REA structures agent work in three steps: decompile, understand, recreate. Decompile opens the app and recovers readable code, strings and names. Understand follows the code across application layers until the agent can explain the feature for real. Recreate turns the finding into a working feature in your own project, in the same coding session. The project is blunt about limits: it does not recover original source code and does not automatically clone applications.
Architecture in practice
Two integration surfaces carry the same capabilities: a CLI and an MCP server. Setup registers the MCP tooling with detected agents — Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf — as one transaction with a bundled routing skill, additive and backup-first. The deep-analysis layer is provider-based: Hopper on macOS, or a caller-selected Ghidra installation on Linux supplying read-only inventory, decompilation, xrefs, CFG and function dossiers. A FIFO bridge serializes Hopper’s single-threaded Python API; decompilation text is cached per document and procedure, invalidated on rename or comment mutation. That cache invalidation discipline is the same idea teams apply to serving-layer caches: reuse aggressively, invalidate precisely.
Evidence as a first-class type
The engineering decision worth copying is reproducible Evidence v2 records: every conclusion carries the trail that produced it, and truthful unknowns are successful results rather than failures. Exit codes encode that contract — partial or truncated evidence still exits 0, while policy, permission or integrity problems exit 1 with a structured failure category. It is the observability mindset production teams already demand from LLM observability setups and evaluation pipelines in CI, applied to analysis output.
Local by design
Analysis runs entirely on the local host; REA never uploads the target application to a hosted service. For agent platforms this is a meaningful boundary — agent tool permissions discussions tend to assume the tool can phone home. Here the data flow is: binary stays local, only chosen context slices reach the language model. Setup honors the same conservatism: nothing preselected, exact paths printed before changes, No as the default answer.
What is next
The roadmap extends the same agent workflow to APIs, protocols, mobile artifacts, firmware and version differences. Requirements today: Node.js 22.19+ or 24.11+, macOS 12+, Ubuntu 24.04+, Fedora 41+ or 64-bit Arch. For engineers, the interesting takeaway is not the reverse engineering itself — it is the pattern: wrap a specialist domain behind a CLI plus MCP, make evidence reproducible, and agents become operators of tools nobody had time to learn.