A new open-source project wants to give coding agents a proper reverse-engineering toolkit. REA, by developer morluto, ships as a Node.js command-line tool and an MCP server that plugs into mainstream agents — Claude Code, Codex, Cursor, Gemini CLI, Windsurf, VS Code and others — and gives them tools to inspect applications for which they do not have the source code.

The pitch is specific: spot a feature you like in an application, ask your agent to investigate it with REA, and have the agent explain how it works — evidence included — then build a version for your own project in the same session. REA connects to the disassemblers Hopper or Ghidra and exposes a large catalog: 39 native-inspection tools (functions, pseudocode, assembly, strings, symbols, cross-references), 14 investigation workflows, artifact and package inspection for APK, IPA, ASAR, plists and more, plus browser observation through the Chrome DevTools Protocol.

REA's design choices are as notable as its capabilities. Analysis runs locally — the project says it has no hosted analysis service — and results carry evidence, locations, confidence and explicit limitations. REA does not claim to recover original source code or to clone an application automatically, and it labels imported decompiler output as analyst inference. Hopper is separate, licensed software, though the project can install it with your approval; Ghidra is supported in a read-only mode with 22 operations, and Windows Ghidra support is currently unavailable pending work on process ownership and path-safety checks.

The project is MIT-licensed and installs through npx, with a doctor command for diagnostics and a snapshot mechanism that caches analysis results so the same query can be answered without relaunching a provider. There is also a workflow layer: on GitHub the README walks an agent from opening a binary, to finding strings and procedures, following cross-references, reconstructing control flow, decompiling routines, and finally building the feature in the user's own stack.

Within a day the repository drew thousands of stars, a sign of how quickly agentic tooling is moving beyond writing new code and into understanding software that already exists. The legal and ethical questions that travel with decompilation — licence terms, interoperability and copyright — remain the user's responsibility, and the project is explicit about that boundary.