REA Hands Coding Agents a Disassembler, and 2,963 Stars Followed in a Day
Software / news
REA Hands Coding Agents a Disassembler, and 2,963 Stars Followed in a Day
The MIT-licensed toolkit from a developer called morluto wires Ghidra, Hopper and a JavaScript analyser into agents over MCP, and its README pitches rebuilding a feature you have only seen running.

A GitHub project called REA, short for Reverse Engineer Anything, gained 2,963 stars in a day and stood at 7,881 total on Tuesday, according to GitHub's trending list. It lets a coding agent such as Claude Code, Codex or Cursor take apart an installed app and report back with evidence. Its README goes further: "understand a feature, then build your own version in the same coding session."
Stars are attention, not adoption. The repository's own numbers say it is small: Trendshift's page for the project lists three contributors, and GitHub's trending page names morluto, N0zoM1z0, rudycelekli, kaoru0822-kitauji and github-actions. Trendshift had it at number three on GitHub Trending on Oct. 6, and at 7,500 stars on its own snapshot, which is why the two star counts here differ.
What setup changes on a machine
The install is npx rea-agents setup, or npm install --global rea-agents followed by rea setup. The README says setup "registers REA with selected agents," adds access through MCP, the Model Context Protocol that lets agents call external tools, installs workflow instructions, and can install Hopper with the user's consent. It also says setup backs up existing configurations and shows the changes before applying them.
That is a tool writing into the config files of every agent it finds. The prompt before the write is the safeguard, and the backup is the undo.

Which engines do the work
REA does not decompile anything itself. It drives other tools and asks them for evidence.
| Backend | What it handles | Requirement in the README |
|---|---|---|
| Ghidra, the open-source framework from the NSA | Native binaries | Ghidra 12.1.4 and a 64-bit JDK 21 |
| Hopper Disassembler | Native binaries on macOS and Linux | Proprietary, separate licence, demo mode with vendor limits |
| Static JavaScript analysis | Unpacked apps and ASAR bundles | Node.js 22.19 or later, no engine needed |
The README lists Mach-O, ELF and PE binaries, Electron apps, .NET assemblies, Android APKs and websites through Chrome's debugging protocol. Windows support through Ghidra is marked experimental and read-only. Supported hosts are macOS 12 and later, Ubuntu 24.04 and later, Fedora 41 and later, and 64-bit Arch Linux.
The limits the README states
The README says REA "does not recover original source code," that dynamic and ambiguous code relationships can stay unresolved, and that process capture records behaviour without proving causation from correlation. The sentence a security-minded reader will stop on is a different one: process capture runs "with your user permissions" and is not a sandbox. Pointing an agent at an unknown binary and letting it run that binary is the same risk as running the binary yourself.
The open issue tracker shows where it breaks. Of 68 open issues, one reports a RangeError: Invalid string length on large JavaScript targets, and another reports an unreadable_output failure on Obsidian 1.12.7, whose ASAR bundle is 24 MB. Version 4.0.1 shipped on Oct. 5 with one change: a fix to "allow npm propagation time" in the release process.
What the MIT licence does not cover
REA is MIT licensed, so the tool is free to use. That licence covers REA. It says nothing about the software the tool is pointed at. Whether rebuilding a proprietary app's feature from its binary is permitted turns on that app's terms and the reader's jurisdiction, and the README's pitch of rebuilding in the same session does not address either.
Agent projects climbing GitHub trending on stars alone are a pattern, and the TesterArmy e2e framework was another. REA also lands alongside OpenAI's rating of its newest model as critical in cybersecurity, which puts agents that can read binaries in the same conversation as agents that can write exploits.
The maintainers have not said what the next release will change. The 68 open issues, including requests for an IDA Pro integration and .NET NativeAOT metadata recovery, are the public roadmap.
Sources
More in Software
- 01VB6 Studio Web 0.6.0 Rebuilds Visual Basic 6 in a Browser, Minus COM and OCXWieslaw Soltes's MIT-licensed project reads .vbp project files and exports standalone HTML, but its README rules out the native components that classic VB6 programs lean on.
- 02Polars 2.0 Makes Streaming the Default and Stops Promising Row OrderThe release, announced Oct. 6 by creator Ritchie Vink, adds no headline feature, but a join or group-by that used to return rows in input order may now return them in any order.
- 03Cloudflare's Web Search API Passes Through Exa, Linkup and Ceramic.ai PricesThe beta, announced Oct. 2 through AI Gateway, adds no markup, so the bill depends on which provider string a developer types and the launch post prints no price.
- 04TesterArmy's e2e Gained 1,398 Stars in a Day. Its Docs Publish No Accuracy FiguresThe Apache-2.0 framework lets an agent drive an app from a plain-English goal, then replays the recorded steps. The one independent benchmark of its decision-model option tested a different job.