October 11, 2026
Closed source was mostly friction
REA gives a coding agent the tools reverse engineers already use. It does not return source code. It makes the inside of a compiled app cheap to read.

REA stands for Reverse Engineer Anything. It is an MCP server and a CLI that lets a coding agent look inside software it has no source code for. The repo has passed 80,000 stars.
What it is
REA is not a decompiler. It wraps the ones reverse engineers already use: Ghidra, Hopper and IDA. The agent gets plain tools on top of them. Open this binary, find the strings, follow the calls.
The target list is long. Native binaries, Electron apps, .NET assemblies, Android APKs, firmware, websites, saved network captures and EVM bytecode.
Setup is one command.
npx rea-agents setup It shows what it will change, backs up your agent config and asks before it writes.
What you get back
You do not get the original source. Compilation throws that away and nothing brings it back.
You get pseudocode, assembly, strings, call paths and network activity. The README says results include the evidence and the limitations behind each conclusion. That part matters most to me. An agent that says “this is how it works” without showing where it looked is a guess.
In the video above, Rob from Switch Dimension tests it on his own app. He builds a small vault with an unlock rule, strips every function name and hides the source. The agent opens 242 anonymous functions, finds the check and writes a generator for valid codes. The app never had a generator. The agent understood the rule and wrote something new.
Friction was the protection
None of this was impossible before. It was slow, specialised and expensive, so almost nobody did it. That cost protected a lot of shipped software.
If you ship a desktop app, a mobile app, a game or a large JavaScript bundle, assume an agent can map how it works. I do not think that is a disaster. The code was rarely the moat. What runs on your servers, your data, your users and how fast you ship still are.
Where I would point it
- At apps on my own machine, to see what they send home.
- At my own old builds where the source is gone.
- At a feature I admire, to learn how it handles sync or search.
I would not point it at a competitor to clone a product. That is legally risky and it misses the point.
Before you run it
Runtime capture runs the target with your user permissions. REA is not a sandbox. A binary you know nothing about can also carry text written to steer your agent. Run unknown targets in an isolated machine and keep approval prompts on.
The licence is MIT and the disclaimer is clear: you are responsible for having the right to inspect what you inspect. Your own software, open source binaries and things you are authorised to test are safe ground.