REA is a reverse-engineering tool that uses AI agents to investigate software behavior and binaries without requiring source code access.
The tool solves the problem of understanding how features work in closed-source applications by automating the reverse-engineering workflow. Instead of requiring operators to manually choose tools, learn their APIs, move evidence between programs, and decide what to inspect next, REA gives agents a consistent interface for investigation. The agent can decompile applications to recover readable code and strings, follow execution paths to understand how features work, and then help recreate those features adapted to a different stack. The tool supports deep native analysis through Hopper or Ghidra on Linux and macOS, experimental Windows x64 PE analysis, execution-free managed PE and CLI triage, controlled process capture, passive observation of websites and Electron applications, JavaScript reconstruction with source maps, and provider-neutral graphs for connecting application layers.
Developers should choose this tool when they need to understand closed-source applications at the binary level or want to reverse-engineer specific features for adaptation into their own products. It suits projects where source code is unavailable and manual reverse engineering would be time-consuming. The tool is designed to work with AI agents through a Model Context Protocol integration, making it most useful for teams already using agent-based development workflows. REA explicitly does not claim to recover original source code or automatically clone applications, so expectations should be set around understanding and recreation rather than perfect reproduction.
The project shows active development with multiple language translations of its documentation, indicating sustained effort to reach a broader audience. The tool maintains a structured investigation model with clear phases and provides reproducible evidence records for tracking how conclusions were reached. The roadmap extends the agent workflow beyond current capabilities to cover APIs, protocols, mobile artifacts, firmware, and version comparisons, suggesting ongoing expansion of the investigation toolkit.