REA Reverse-Engineering Agent Toolkit Surges on GitHub
REA, an MIT-licensed toolkit that lets coding agents reverse engineer apps and binaries, gained 2,956 GitHub stars in a day after its 4.1.0 release on 6 October 2026.
PromptCrates Editorial
Staff Writer

REA, an open-source toolkit that lets coding agents reverse engineer compiled apps, binaries and websites, gained 2,956 stars in a day on GitHub, the most of any repository on the daily TypeScript trending list when PromptCrates checked at 01:11 UTC on Wednesday, 7 October 2026. The jump follows version 4.1.0 of the rea-agents package, released on Tuesday, 6 October, which added Android app analysis, firmware inspection and an IDA Pro provider. The MIT-licensed morluto/rea repository had 9,486 stars at the same check.
What REA does for coding agents
REA stands for Reverse Engineer Anything. Its README describes it as one MCP server for reverse engineering across binaries, applications and runtime behaviour, with the same capabilities available from a command-line tool. It connects an agent to tools for inspecting native binaries, JavaScript and Electron apps, .NET assemblies and websites.
The project frames its workflow in three steps: decompile, understand and recreate. In the README's example, a user asks an agent to work out how search works in a notes app, show the evidence and build a similar feature for their own project. REA handles the analysis, and the agent writes the new code with its normal editing and testing tools.
The README walks through that flow as six steps. The agent opens and identifies the binary, searches strings and procedure names for clues, follows cross-references to the code that uses them, rebuilds the relevant call graph and decompiles the routines involved, using tools with names such as open_binary, search_strings, find_xrefs_to_name and batch_decompile. Only the sixth step, building the feature, is left to the agent itself. Installation starts with a single npx command. The README lists macOS 12 or newer, recent Ubuntu, Fedora or Arch Linux releases, and Node.js 22.19, 24.11 or 26 and later as requirements, and says the APK tools use a separately supplied JADX and Java without running the app or an emulator.
The README is explicit about limits. It says REA does not claim to recover original source code or automatically clone an application, and that results include the evidence and limitations behind each conclusion. Native analysis can use an existing installation of Hopper or Ghidra, and setup can install Hopper with the user's approval. Static JavaScript analysis needs neither engine.
According to the README, the setup command can register REA with Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf, Devin, OpenCode, Antigravity, GitHub Copilot CLI, Command Code and VS Code. Other agents that can run a local MCP server can use a manual configuration.
What changed in REA 4.1.0 and 4.0.0
The 4.1.0 release notes, dated 6 October, list several new analysis targets. Android APK files can now be inspected statically using headless JADX. Firmware images can be analysed through Binwalk and Unblob. A new IDA provider adds read-only GUI and headless MCP access, and the Ghidra provider gains read-only analysis of Windows x64 programs, DOS COM files and optional NativeAOT metadata recovery.
The same release adds atomic function annotation edits in Ghidra, support for registering REA with Command Code, and fixes including Windows handling for extracted file trees. The npm registry shows 4.1.0 published at 18:06 UTC on 6 October.
Version 4.0.0, released the previous day, carried breaking changes. Its notes say it removed permission configuration and policy commands, approval fields, filesystem scope inputs and fixed confirmation options, and that process capture now inherits the host environment. It also retired controlled replay, several runtime planning tools and redundant string-tracing tools, so existing users need to refresh tool schemas and migrate removed fields.
The README's tool catalog now lists 41 native inspection tools, 14 investigation workflows, five Android APK tools, nine browser observation tools, two firmware tools and 21 workspace and observation tools, among other groups.
Safety, licensing and local-only analysis
REA's README says analysis runs locally and that the project has no hosted analysis service. It talks to Hopper and Ghidra through authenticated private local sockets and to IDA through its configured local MCP registration. The README adds that the user's agent or model provider has its own data policy, which users should review separately.
Analysis tools and launched targets run with the user's own permissions, according to the security section, and native interface capture on macOS depends on Accessibility and Screen Recording access. For websites, REA can attach to an already running Chrome-family browser over a local debugging endpoint. The README says the passive browser tools do not navigate, click or run page JavaScript, and that credentials, cookies, authorization headers and raw payload values are not retained.
The analysis engines are separate products. The README says Hopper keeps its own license, and that REA does not install or include Ghidra or Java. IDA support works through what the project calls a bring-your-own upstream adapter.
The roadmap lists runtime observation of native apps through tools such as LLDB and Frida, plus evaluation of Binary Ninja, Rizin and LIEF, as later work.
Adoption signals behind the GitHub surge
The repository was created on 14 April 2026, according to GitHub's API, almost six months before this week's surge. The rea-agents package on npm recorded 1,291 downloads in the week from 28 September to 4 October, according to npm's public download counts, before the 4.x releases landed.
Figures on the GitHub TypeScript trending page change through the day, so the 2,956 count is a single snapshot taken at 01:11 UTC. The project also maintains a Discord community and README translations in Chinese, Japanese, Korean and Arabic.
REA joins other agent tooling that has climbed GitHub's charts and been covered by PromptCrates, including Chrome DevTools MCP as a browser bridge for agents, the TesterArmy e2e testing framework and the Superpowers agentic skills framework.
- morluto/rea repository on GitHub
- REA 4.1.0 release notes
- GitHub trending: TypeScript, daily
- rea-agents package on npm
- PromptCrates: Chrome DevTools MCP surges as agent browser bridge
- PromptCrates: TesterArmy e2e trends on GitHub after 0.17 release
- PromptCrates: Superpowers climbs GitHub as agentic skills framework


