Agent tools and protocols

morluto/

rea

MCP server and CLI that connects an AI agent to Hopper, Ghidra, IDA, and other tools for reverse engineering binaries, apps, and captures.

What’s new here

REA registers a single MCP server and CLI that routes to whichever engine fits the target: Hopper, Ghidra, or IDA for native code; JADX for Android APKs; a Chrome-family browser for websites; pwntools-backed ELF and crash readers; and static readers for .NET assemblies and EVM bytecode. Every result includes the evidence and stated limitations behind each conclusion, so the agent can ask follow-up questions rather than treat findings as ground truth.

What it does

REA gives an AI agent (or a human at the terminal) a set of tools for inspecting a target without its source code.

For native binaries it drives an existing Hopper, Ghidra, or IDA installation and returns pseudocode, assembly, strings, symbols, and call references. For JavaScript and Electron apps it reads modules, imports, source maps, IPC boundaries, and native add-on relationships from a directory or ASAR without executing anything. For .NET assemblies it reads metadata and CIL instructions statically. For Android it runs headless JADX to decompile APKs and can also talk to a live device or emulator through adb. For websites it drives a Chrome-family browser and returns page structure, scripts, network observations, and requested screenshots. Saved network captures (HAR, or native mitmproxy captures via mitmdump on Linux) yield requests, responses, exposed payloads, and source locations. Firmware images go through Binwalk or Unblob on Linux.

The npx rea-agents setup command registers the MCP server with Claude Code, Codex, Cursor, Gemini CLI, Grok Build, and other agents, and writes matching workflow instructions. The same analysis is available from the rea CLI without an agent in the loop.

Who it’s for

Security researchers and CTF players who want an agent to trace code paths in binaries or APKs. Developers who want to understand how a closed app implements a feature before building their own version. Developers doing routine static analysis of JavaScript bundles, .NET assemblies, or EVM bytecode who want an agent to handle the navigation and summarization.

Try it

Run setup once with Node.js 22.x (>=22.19), 24.x (>=24.11), or 26+ installed:

npx rea-agents setup

Restart your agent after setup. To analyze a JavaScript or Electron app from the terminal immediately:

npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --json

To install the rea command for regular use:

npm install --global rea-agents
rea --help

To update an installed CLI:

rea update

How mature is it

67,533 stars and 14,242 forks. 67 contributors. 34 releases; the latest (rea-agents-6.3.0) shipped 2026-10-09, one day before this data was collected. More than 100 commits in the last 90 days (the count is capped, so the real number is higher). 140 open issues and pull requests. MIT license. The repo was created 2026-04-14, so it reached this star count in roughly six months.