How to have an agent reverse-engineer app internals to replicate features
When you see an app with a feature you want but lack the source code to understand how it works, an AI agent uses this tool to dig into the binary level, explain the principles, and provide evidence. REA is an MCP server and CLI tool that connects agents to reverse-engineering tools so they can manipulate them directly. Analysis runs locally, and every conclusion is presented with its basis and limitations.
The investigation process performed by the agent
The user only needs to ask the agent to understand a specific app's functionality and create a similar one. The agent uses REA to open the binary, search for strings or symbols, and trace where that code is called. It then reconstructs the control flow and decompiles necessary routines into readable code. Throughout this process, the agent does not simply guess; it derives conclusions based on evidence returned by the tools. In the final stage, the agent uses its own file editing and testing tools to implement a feature suitable for the user's project based on what it has learned.
Supported targets and analysis scope
REA analyzes native binaries, JavaScript and Electron apps, .NET assemblies, and websites.
- Native binaries Supports Mach-O, ELF, and PE formats, and integrates with Hopper, Ghidra, and IDA Pro. It inspects functions, pseudocode, assembly, strings, and symbols.
- JavaScript and Electron Performs static analysis without running the app, mapping module structure and native addons. It allows for comparison between builds and feature tracking.
- Websites and browsers Observes page structure and network metadata through a running browser. It focuses on passive observation rather than active manipulation.
- .NET assemblies Inspects metadata and CIL instructions without loading or executing the assembly. It checks declared native dependencies.
Installation and requirements
Installation starts with the npx rea-agents setup command, which involves selecting a supported agent and approving changes. Static JavaScript analysis requires only Node.js and npm, but native binary analysis requires one of Hopper, Ghidra, or IDA Pro. Hopper has a separate license and supports demo mode. Ghidra and IDA Pro are used as installed by the user. Supported operating systems include macOS 12 or later, Ubuntu 24.04 or later, Fedora 41 or later, and 64-bit Arch Linux, requiring Node.js version 22.x or later, 24.x or later, or 26 or later. Windows x64 Ghidra support is experimental and only possible under specific conditions.
Pre-use considerations
REA keeps analysis results locally and does not upload apps to hosted services. However, you must verify the license status and platform compatibility of the native analysis engines. Hopper's demo mode has vendor-defined limitations, so you should review whether a commercial license is needed. When using Ghidra, version 12.1.4 and 64-bit JDK 21 are required, and on macOS, a native decompiler matching the architecture must be installed. The IDA Pro adapter was initially verified only for Windows GUI and x64 headless environments, so other combinations are unverified. Additionally, REA does not claim to restore original source code; decompilation results are pseudocode, not the original source.