2026-10-11 16:33 UTC

REA (Reverse Engineer Anything) releases an open-source toolkit that equips coding agents with native binary, JavaScript, and browser inspection capabilities — including decompilation, call tracing, and runtime observation — to automate reverse engineering workflows for vulnerability research and software analysis.

state: corroboratedheat: lowuncertainty: lowconvergesscott: highreverse-engineering-tools ai-assisted-reversing binary-analysisREA maintainers (morluto)

What is this?

REA (Reverse Engineer Anything) is an open-source toolkit (MIT licensed) by maintainer morluto that equips coding agents with native reverse-engineering capabilities via an MCP server and CLI. It supports decompilation and call tracing of native binaries (using Ghidra/Hopper), static and runtime analysis of JavaScript/Electron apps and .NET assemblies, and passive browser runtime observation — all running locally with evidence-backed results. The project launched in April 2026, has 36.9k GitHub stars, and integrates with Claude Code, Cursor, Codex, Gemini CLI, and other agents. Web snippets confirm the feature set and adoption signals but do not yet surface independent technical validation of the binary analysis depth or evidence model.

Why it matters to Scott

REA is a concrete, widely-adopted (36.9k stars) MCP server that implements the 'agent hands and eyes for reverse engineering' pattern Scott's frameworks argue for: data-archaeology (AI writes the reader on demand), semantic-decompilation (deterministic RE pipeline), ai-legacy-takeover (OHBVP observe/hypothesise phases), and ecosystem-decompilation. It gives coding agents native binary/JS/browser inspection — the exact capability surface his agent-hands-and-eyes and code-first-architecture frameworks predict agents need. This is a dated-receipts moment: a consequential other party has shipped what Scott's canon describes.
ip:concept.data-archaeologyip:framework.semantic-decompilationip:framework.ai-legacy-takeoverip:concept.ecosystem-decompilationip:concept.agent-hands-and-eyesip:source.mcp-as-the-tool-belt-standard-giving-ai-agents-hands-and-eyes-ebookip:framework.code-first-architectureip:framework.agent-native-computingdev:technology.mcpdev:technology.fastmcpdev:technology.claude-codedev:technology.codex-clidev:technology.opencodeip:concept.runtime-containmentip:concept.sandboxed-executionip:framework.agent-provenance-stackip:concept.agent-receiptsradar:actualis-local-coding-agent-observabilityradar:agentshield-offline-agent-scannerradar:aegis-inline-ebpf-agent-containmentradar:abyss-acp-agent-isolationradar:ac2-agent-security-protocolradar:aisle-six-curl-cves
queries asked of Scott's wikis
  • agent tooling MCP server patterns local-first
  • reverse engineering binary analysis automation agents
  • evidence-based agent workflows provenance tracking
  • open-source AI agent ecosystems tool interoperability
  • vulnerability research tooling AI-assisted
  • local inference agent memory knowledge systems

Measured heat

now 5 pts/hpeak 75 pts/hcomments 5/hpeers p65momentum: cooling3 platformsage 75h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

10-08 13:00⭐ origin echo-reconstructedREA gives coding agents tools to inspect programs (native binaries, JS/Electron apps, browser runtime) and explain what they do. Provides np
morluto (REA maintainers) on github (echo) · attributed from hn.story.50028275
—
10-10 00:37first on hacker news · published · +35.6hREA Reverse – Engineer Anything
modinfo
—
10-10 22:22first on r/singularity · published · +57.4hReverse Engineer Anything is a great toolkit, what would you like to see reverse engineered?
jazir55
—
10-10 00:37amplified on hacker news 👑hn.story.50028275
modinfo
peak 705 · 303 comments · 89% of case engagement
10-10 15:39amplified on hacker newshn.story.50034003
rahuljha0403
peak 2 · 1 comments · 0% of case engagement
10-10 22:22amplified on r/singularityreddit.post.1x2rrsi
jazir55
peak 111 · 100 comments · 10% of case engagement
10-11 15:33amplified on r/singularityreddit.post.1x3b6f1
WrongChoices
peak 1 · 0 comments · 0% of case engagement
10-10 01:32our radar first saw it · +36.5hdiscovery anchor: hn.story.50028275—
pace: p94 vs 1243 stories at the 72h mark (now 75h old) — ahead of alphagenome-atlas (1.0x), behind openai-millennium-maths-claim (1.0x)

Evidence (5) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnREA Reverse – Engineer Anything
Retrieved article excerpt

Open article · Retrieved 2026-10-10T01:44:15.397741+00:00

Reverse engineering, with your coding agent

# Find out how software works.

REA gives your agent the tools to inspect a program and explain
what it does.

[See how REA works ↓](https://rea.tools/#what-is-re)
[Setup guide](https://rea.tools/get-started/)
[Showcases →](https://rea.tools/showcase/)

Already know RE?
[Skip to analysis guides →](https://rea.tools/#analysis-guides)

## Set up REA

Copy this into your coding agent:

Your coding agent

Copy

›Install REA and connect it to this coding agent using npx
rea-agents@latest setup. Show me the setup plan for approval,
then verify the installation.

Or run this in your terminal:

`npx rea-agents@latest setup`

Copy

Approve the setup plan, then restart your agent.

## What is reverse engineering?

Finding out how software works by
**examining the program itself.**

The goal: understand a feature well enough to
explain it,
change it or
rebuild it.

One question:
**why does Calculator give 220 for 200 + 10%?**

Before REA · You investigate it
**yourself**

01 Decode branches

02 Trace calls

03 Recover the rule

Original x64 · selected instructions

```
0x180124945: MOV EAX, dword ptr [R13 + 0x18]
0x180124949: CMP EAX, 0x5c
0x18012494c: JZ 0x180124aba
0x180124952: CMP EAX, 0x5b
0x180124955: JZ 0x180124aba
0x18012495b: MOV EDX, 0x64
0x180124960: LEA RCX, [RSP + 0x160]
0x180124968: CALL 0x180122650
0x18012496e: LEA RDX, [R13 + 0x160]
0x180124975: LEA RCX, [RSP + 0x78]
0x18012497a: CALL 0x180109720
0x18012497f: MOV RSI, RAX
0x180124982: MOV qword ptr [RSP + 0x28], RAX
0x180124987: LEA RDX, [RSP + 0x160]
0x18012498f: MOV RCX, RAX
0x180124992: CALL 0x180123190
; … value-copy instructions omitted …
0x180124a14: MOV RDX, RDI
0x180124a17: LEA RCX, [RSP + 0xf8]
0x180124a1f: CALL 0x180109720
0x180124a24: LEA R8, [RSP + 0x30]
0x180124a29: MOV RDX, RAX
0x180124a2c: LEA RCX, [RSP + 0xb8]
0x180124a34: CALL 0x180123c10
```



01 · Which branch?

“**0x5b? 0x5c?** Two jumps to the same
place. Which operators are these?”

Look up the command IDs, then label the branch.

0x5b
:   Divide ÷

0x5c
:   Multiply ×

02 · What do the calls do?

“100 is clear. The calls are just addresses.
**Which one divides? Which value goes in?**”

Inspect the helpers and trace the stored values.

0x64
:   100

…123190
:   Divide

03 · What is the rule?

“This path multiplies by the other input. So
**10% means 10% of 200** after +.”

Name the operands and check both operator paths.

200 × 10 / 100
**20**

Illustrative expert reasoning

**You decode the instructions, follow the calls and reconstruct
the calculation.**

With REA · You ask
**your agent**

### One prompt.

Ask your agent **in plain English.**

Example prompt · Calculator

Copy

›Use REA to inspect Windows Calculator. Why does 200 + 10%
give 220?

Example answer · based on the findings

After +, the % button takes
**a percentage of the first number.**

`10% of 200 = 20`↓**200 + 20 = 220**

REA supplies
:   The handler’s instructions, decompiled code and calls.

Your agent explains
:   Which branch applies, what it calculates and how to rebuild
    it.

Selected assembly from the installed Calculator DLL. The thoughts
and reply illustrate the findings.
[Continue with the Calculator example ↓](https://rea.tools/#calculator)

**Let's try two examples.**
Change a game's speed, then return to Calculator and rebuild its %
button.

Example 01 · Chrome’s dinosaur game

## Why does the dinosaur get faster?

Goal
:   Rebuild the game with
    adjustable speed.

Why reverse engineer it?
:   To reproduce its acceleration, we need
    **the rule in the running game**: how fast it
    starts, how much it increases and when it stops.

Play the reconstruction

6 → 10 → 13

Play
Jump ↑
Restart

Speed 6.0
 Use the
recovered acceleration rule

Original rule: start at 6, then increase toward 13.

Move the slider to set your own speed. Space or Jump clears a
cactus.

REA returned

**The script actually running in the page.** The
agent reads its update function and speed settings, then uses
that rule in a new game.

Example prompt · Dinosaur game

Copy

›Use REA to inspect this dinosaur game. Why does it get
faster? Show the speed rule, then build a small version with
an adjustable speed.

Inspected target:
[wayou’s Chromium-derived browser edition](https://wayou.github.io/t-rex-runner/).

REA · loaded index.js · selected lines

```
if (this.currentSpeed < this.config.MAX_SPEED) {
  this.currentSpeed += this.config.ACCELERATION;
}
```

**Start at 6.** Add **0.001** each
update without a collision, while speed is below
**13**.

[Open the speed lab →](https://rea.tools/examples/dino-lab/)

What each part does

1. 01 · REARead the running game’s scriptReturn its actual code and settings to the agent.
2. 02 · Your agentRebuild the rule, add a controlUse the recovered acceleration in a small game with a speed
   slider.
3. 03 · YouChange the speed and playTry the original acceleration, then choose your own
   pace.


See the script, checks and how to try the analysis

REA inspected the HTTP browser edition through a local debugging
connection and returned the loaded `index.js`,
including its source and digest.

Selected settings from the inspected script

```
ACCELERATION: 0.001,
MAX_SPEED: 13,
SPEED: 6
```

We called the original game’s update function in a controlled
browser check, with obstacles and automatic scheduling disabled.
After 4,000 updates, speed was 10.0; after 10,000, it was 13.0,
rounded to one decimal.

The new mini-game keeps that speed rule. Its drawing, jumping and
collision code are a small teaching implementation.
[Open the lab](https://rea.tools/examples/dino-lab/) to see the new code
and run the same speed check.

To inspect the target yourself, follow the
[browser connection steps](https://rea.tools/guides/browser/#prepare)
using
[the dinosaur page](https://wayou.github.io/t-rex-runner/). Give your agent that page URL and your local debugging
endpoint, then copy the prompt above.

[Inspected speed code](https://github.com/wayou/t-rex-runner/blob/5455bfa408ec6b707c7300ff194b7390733a766d/index.js#L565-L571)
·
[Chromium Authors · BSD license](https://rea.tools/assets/licenses/dinosaur.txt)

Example 02 · Windows Calculator

## Rebuild Calculator’s % button.

We saw why **200 + 10% gives 220.** Now let’s recover
the rules for both + and ×, and try them.

Goal
:   Build a small calculator that handles
    both + and × correctly.

Why reverse engineer it?
:   The same button uses
    **different rules after + and ×.** We inspect the
    installed app to find which number the percentage is applied to.

Try the calculation

200 + 10%

200 × 10%

200 +
**20**

%

=

Reset

10% of 200 = 20. Then 200 + 20 = 220.

Interactive illustration of the inspected percentage rule.

REA returned

**One branch divides by 100. The other also multiplies by the
first number.**
The agent uses both to recreate the % button.

For this example, `previous = 200` and
`current = 10`.

Example prompt · Rebuild the % button

Copy

›Use REA to inspect Windows Calculator’s % button. Recover
the rules after + and ×, then build a small calculator that
uses both.

Readable summary of the % handler

```
if (operation == multiply || operation == divide) {
  percent = current / 100;
} else {
  percent = current * previous / 100;
}
```

With +
:   **Take 10% of the first number.**`10% of 200 = 20 → 200 + 20 = 220`

With ×
:   **Turn 10% into 0.1.**`200 × 0.1 = 20`

From the installed app to a working % button

1. 01 · REA reads calc.exeIt launches the Calculator appThe code opens `ms-calculator:`. The agent then
   selects the installed app’s library.
2. 02 · REA reads the libraryReturn the % handler’s codeThe function checks the operator and uses the constant
   `100`.
3. 03 · Your agent interprets itExplain and reproduce the rulesCrosscheck the branch with Microsoft’s source, then try + and
   × above.

See the real code and how the answer was checked

REA · selected original instructions

```
0x180124945: MOV EAX, dword ptr [R13 + 0x18]
0x180124949: CMP EAX, 0x5c
0x18012494c: JZ 0x180124aba
0x180124952: CMP EAX, 0x5b
0x180124955: JZ 0x180124aba
0x18012495b: MOV EDX, 0x64
```

Operator IDs · Microsoft’s source

```
#define IDC_MUL 92      // 0x5c
#define IDC_DIV 91      // 0x5b
#define IDC_PERCENT 118 // 0x76

0x64 = 100
```

Inspected with REA 4.1.0: Windows Calculator 11.2508.4.0, x64. The
readable summary uses names from Microsoft’s public source to
explain the recovered branch.

[Percentage implementation](https://github.com/microsoft/calculator/blob/d125246a4e19842ce1332e6c7839cf0e110027d8/src/CalcManager/CEngine/scifunc.cpp#L98-L111)
·
[Microsoft’s test cases](https://github.com/microsoft/calculator/blob/d125246a4e19842ce1332e6c7839cf0e110027d8/src/CalculatorUnitTests/CalculatorManagerTest.cpp#L350-L370)
· [Native setup guide](https://rea.tools/guides/native/)

Your first investigation

## Try REA on a small app.

Download our Notes example, trace its CSV export, and check one
changed input.

[Try the guided example](https://rea.tools/first-investigation/)

## Want to go deeper?

Tell your agent what you want to understand or build. With REA,
you can work together on anything from
**cloning this website** to
**reconstructing a game from its executable.**

Example prompt · Website

Copy

›Use REA to inspect https://rea.tools/. Clone this website
for me.

Yes, this one.

Example prompt · Game reconstruction

Copy

›Use REA to reconstruct this game from its executable.
Recover the gameplay logic in C and test it against the
original.

[See the DX-Ball case study →](https://rea.tools/showcase/dx-ball/)

For setup and analysis steps, choose your target:

### Native binaries

Inspect functions, strings, references and call relationships in
executables and libraries.

[Native analysis guide](https://rea.tools/guides/native/)

### JavaScript & Electron

Map modules, routes, IPC and native dependencies from an
application folder or ASAR archive.

[Application workflows](https://rea.tools/guides/javascript/)

### Browser & runtime activity

Capture selected browser or process activity, then compare the
results across runs.

[Browser observation guide](https://rea.tools/guides/browser/)

## Any questions?

[Read the FAQ](https://rea.tools/faq/),
[chat with us on Discord](https://discord.gg/GkcryMnJDM),
or
[open a GitHub issue](https://github.com/morluto/rea/issues/new/choose)
for bugs and feature requests.
modinfo753323
🟧 echo.github ⭐REA gives coding agents tools to inspect programs (native binaries, JS/Electron apps, browser runtime) and explain what they do. Provides npmorluto (REA maintainers)——
🟧 hnAsk HN: Have you checked REA(reverse engineer anything) GitHub repo?rahuljha040321
🟠 redditReverse Engineer Anything is a great toolkit, what would you like to see reverse engineered?
singularity
jazir55111100
🟠 redditThis reverse-engineering repo could massively accelerate AI coding capabilities.
singularity
WrongChoices1215

Interpretation history

Decision trace