REA, short for Reverse Engineer Anything, is an open-source reverse-engineering toolkit that connects AI agents to local analysis workflows. The GitHub repository describes it as one MCP for reverse engineering across binaries, applications, and runtime behavior. A user can ask an agent to understand how a feature works, inspect the target, collect evidence, and explain the behavior with limitations instead of only returning a guess.
The project is aimed at software teams, security researchers, and builders who need to analyze systems without source code. REA covers JavaScript and Electron applications, native binaries, firmware-style targets, managed code, packet captures, websites, app behavior, and runtime traces. The documentation points to guides, showcases, MCP contracts, agent prompts, a CLI guide, and a product catalog, which makes it more than a one-off prompt pack.
REA can be used from AI agents through MCP or directly from the terminal. The documented setup path is `npx rea-agents setup`, which lets users choose supported agents, reviews proposed configuration changes, adds the REA MCP server, installs matching workflow instructions, and backs up existing configuration. Supported agent examples include Claude Code, Codex, Cursor, Gemini CLI, and other MCP-capable clients through manual registration.
The terminal path matters because reverse engineering work often needs repeatable evidence. The README shows commands such as analyzing a JavaScript or Electron application directory with `npx -y rea-agents@latest analyze-javascript-application /absolute/path/to/app --json`. Findings are expected to include modules, imports, Electron boundaries, code references, evidence, and unknowns.
REA is not a magic decompiler and should not be treated as a replacement for expert review. It is best viewed as an agent-facing workbench around local reverse-engineering tools. Users still need legal permission to inspect a target, local tooling for the target type, and judgment about what the evidence proves. The repository is MIT licensed, and the visible package path is `rea-agents`, so the software itself is free while users bring their own agent and compute environment.
For OpenTools readers, the practical test is whether the project removes work from a real builder workflow. This listing focuses on documented setup paths, concrete capabilities, limits, pricing signals, and the kinds of teams that can safely use the product.
Teams should still run their own review before using any agent-connected tool on sensitive data. Check what runs locally, what touches third-party APIs, which permissions are granted, and whether the workflow can be scoped to a test project before production use.
The page avoids unsupported claims. When the source names a license, package, install command, browser, runtime, or feature, the listing uses that source-backed fact. When pricing or limits are not public, it says so instead of guessing.