morluto · 2026-10-06 · major
REA 4.1 — the agent reverse-engineering kit now reads Android APKs and firmware
REA 4.1 adds Android APK analysis with JADX, firmware analysis with Binwalk and Unblob, and IDA providers to the open-source CLI and MCP server that lets coding agents reverse engineer apps. It follows the breaking 4.0 release.
Point your coding agent at an app or binary and it can decompile it, trace a feature and show the evidence.
Key specs
| GitHub stars | 8,940 |
|---|
Quick facts
| Version | 4.1.0 (after 4.0.0 on Oct 5) |
|---|---|
| New targets | Android APKs, firmware images |
| Analysis engines | Hopper, Ghidra, IDA Pro |
| Works with | Claude Code, Cursor, Codex, Gemini CLI and other MCP agents |
| License | MIT |
| Install | npx rea-agents setup |
What is it?
REA (Reverse Engineer Anything) 4.1, released on October 6, 2026, adds static Android APK analysis through headless JADX and firmware analysis through Binwalk and Unblob. REA is an open-source CLI and MCP server that gives AI agents decompilation, tracing and evidence tools for software they have no source code for. The repo gained nearly 3,000 GitHub stars in one day.
How does it work?
An agent calls REA over MCP (or a person uses the rea CLI) to decompile a target, follow its code between functions and record an Evidence bundle with confidence levels and known gaps. Native analysis runs through Hopper, Ghidra or — new in 4.1 — read-only IDA GUI and headless providers. The 4.0 release a day earlier removed the replay and permission-policy features and added native inspection primitives.
Why does it matter?
Security researchers and developers who need to understand a closed app can hand the slow parts of reverse engineering to an agent while keeping every claim tied to evidence. All analysis stays local, with no upload to a hosted service. With APKs and firmware covered, the same workflow now reaches mobile apps and embedded devices.
Who is it for?
security researchers and developers studying closed-source apps
Frequently asked questions
- Which AI agents work with REA?
- REA's setup wizard can register its MCP server with Claude Desktop, Claude Code, Cursor, Windsurf, Codex, GitHub Copilot CLI, Gemini CLI, Devin, OpenCode, Antigravity, Command Code and VS Code. Any other agent that supports local MCP servers can use REA through manual configuration.
- What changed in REA 4.0?
- REA 4.0.0, released October 5, 2026, is a breaking release. It removed controlled replay, the finite replay machine and the permission-policy commands, and changed setup to refresh only existing REA-owned registrations unless --all-detected is passed. It added native inspection primitives, dispatch traces and DOS MZ analysis.
- Does REA send my app to the cloud?
- No. REA runs its analysis locally and does not upload the target app to a hosted service. Its results are Evidence bundles with provenance and confidence levels, and the project says plainly that it does not claim to recover the original source code.
- Which systems does REA run on?
- REA supports macOS 12+, Ubuntu 24.04+, Fedora 41+ and 64-bit Arch Linux, with Node.js 22.19+, 24.11+ or 26+. Windows support is limited to an experimental read-only Ghidra path for native x86-64 applications, and process capture still needs macOS or Linux.
Try it
npx rea-agents setup