REA (Reverse Engineer Anything) is an open-source bridge between AI assistants such as Claude Code and Cursor and tools including Ghidra, IDA Pro and Hopper.
It supports examination of software without its original source code, across formats ranging from native executables and JavaScript to Android apps and websites.
The project returns findings with supporting evidence and stated limits.
REA does not replace tools like Ghidra, IDA Pro, and Hopper. It connects these tools to the assistant. It can examine executable files, JavaScript, Electron and Android apps, .NET software, firmware—the software embedded in devices—and web pages. It also supports examining some programs while they are running. Researchers can also do the same tasks by typing commands into a command window on a computer.
REA returns findings along with supporting evidence and states the limits of the examination. The researcher can request more information or write and test an implementation based on the findings.
For deep examination of native executables—programs in a format that runs directly on the computer—Ghidra, IDA Pro, or Hopper must already be installed. Installing REA may install Hopper, if the user approves. JavaScript and .NET examination do not require any of these tools.
The installation requires a supported version of Node.js and npm and can configure REA for Claude Code, Cursor, Codex, Gemini CLI, and Grok Build. The user selects which helper they want and approves the changes. The installation keeps copies of the existing settings, and after completion, the helper needs to be restarted. Other helpers can be connected with manual configuration, as long as they support the specific way to connect to local servers. According to the project page, the operating systems supported depend on the provider of the examination tool chosen.
The REA developers present two examples. In a test with the DX-Ball game, they report that the reproduction of the calculation that places the sound passed 3.205 tests compared to the original code and reproduced all 63 bytes of the function. In another example, REA followed the way the Notion application handles the clipboard through different parts of it.
These examples do not prove that REA can completely reconstruct every program. The results depend on the program, the platform, and the tools required.
Examining static JavaScript and .NET files does not run the application. In contrast, recording the operation of a program may require launching it or operating it with user privileges.
The scan is done locally on the user's computer, but the assistant receives the findings. How the data is used also depends on the assistant provider's policies. Therefore, a local scan does not guarantee that all findings remain on the device.
Top comments (1)
tr.ee/dev-to