REA Gives Your Agent Ghidra, and GitHub Gave It 3,000 Stars in a Day
Top of GitHub trending on Tuesday with 2,963 stars in a day: REA, short for Reverse Engineer Anything, an MCP server that connects a coding agent to reverse-engineering tools. The pitch on the README is blunt. See a feature in someone else's app that you want. Ask your agent to investigate it. REA inspects the app without source, explains how the feature works, shows the evidence, and builds a version for your project.
The tool catalog is what makes it more than a wrapper. Native binaries (Mach-O, ELF, PE, Mac .app) go through Hopper or Ghidra, with a read-only IDA adapter. JavaScript and Electron apps get module maps, source maps, routes, IPC channels and storage without running the app, plus build-to-build diffs. .NET assemblies get metadata and CIL inspection. Websites get passive observation inside your existing Chrome: page structure, network metadata, script evidence, screenshots. Version 4.1.0, released Tuesday, added static Android APK analysis through headless JADX, firmware unpacking through Binwalk and Unblob, Windows x64 read-only analysis in Ghidra, and atomic function annotations. Analysis runs locally, and every conclusion comes with its evidence and its limitations.
Setup is one command, npx rea-agents setup, which registers the MCP server with whichever agents you select and installs matching workflow instructions. The repo was created in April, is MIT licensed, and sits at 8,889 stars, so a third of them arrived today. The project is clearly in a release sprint: 4.0.0 and 4.0.1 shipped Monday, 4.1.0 Tuesday, with commits landing through the evening.
Why it is trending is more interesting than what it is. A year ago the frontier for coding agents was "write this feature". The frontier now is "that app has the feature, go find out how and bring it back". That is a different legal and competitive posture, and REA's README does not pretend otherwise. It is Mistral's cyber argument from the same day in a smaller frame: the capability exists, the question is who gets to run it.
Link: github.com/morluto/rea
← Back to all articles
The tool catalog is what makes it more than a wrapper. Native binaries (Mach-O, ELF, PE, Mac .app) go through Hopper or Ghidra, with a read-only IDA adapter. JavaScript and Electron apps get module maps, source maps, routes, IPC channels and storage without running the app, plus build-to-build diffs. .NET assemblies get metadata and CIL inspection. Websites get passive observation inside your existing Chrome: page structure, network metadata, script evidence, screenshots. Version 4.1.0, released Tuesday, added static Android APK analysis through headless JADX, firmware unpacking through Binwalk and Unblob, Windows x64 read-only analysis in Ghidra, and atomic function annotations. Analysis runs locally, and every conclusion comes with its evidence and its limitations.
Setup is one command, npx rea-agents setup, which registers the MCP server with whichever agents you select and installs matching workflow instructions. The repo was created in April, is MIT licensed, and sits at 8,889 stars, so a third of them arrived today. The project is clearly in a release sprint: 4.0.0 and 4.0.1 shipped Monday, 4.1.0 Tuesday, with commits landing through the evening.
Why it is trending is more interesting than what it is. A year ago the frontier for coding agents was "write this feature". The frontier now is "that app has the feature, go find out how and bring it back". That is a different legal and competitive posture, and REA's README does not pretend otherwise. It is Mistral's cyber argument from the same day in a smaller frame: the capability exists, the question is who gets to run it.
Link: github.com/morluto/rea
Comments