Open source contribution · TypeScript · MCP · AI Agents · Reverse Engineering
morluto/ rea
Open-source project that gives AI agents reverse engineering tools to understand how software works, from native binaries to websites.
- 5 PRs under review
- 101.4k GitHub stars
- Oct 11, 2026 first PR
The project
REA (Reverse Engineer Anything) connects coding agents such as Claude Code, Codex and Cursor to reverse engineering tools, which also work straight from the terminal. With it, an agent can examine apps without their source code: native executables, JavaScript and Electron apps, .NET programs, Android apps and websites.
Analysis runs on the user's own machine, and every answer carries the evidence and limitations behind its conclusion. The agent uses those results to ask follow-up questions, explain the behavior, or write and test an equivalent implementation. Published case studies include tracing how Notion handles the clipboard and rebuilding calculations from older games out of their original binaries.
How each PR was made
-
One problem per PR
Each PR fixes a single thing with the smallest possible change. That keeps reviews simple, lowers the risk of side effects and lets one change be reverted without taking others with it.
-
The problem becomes a test
Fixes come with automated tests that cover the case that used to fail, so the problem cannot come back unnoticed.
-
The project's own bar
Formatting, static analysis and the full test suite run in the project's continuous integration, and a change only lands after the maintainer's review.
-
Written for the reviewer
Each PR description explains the problem, the change and how it was tested, so the maintainer can decide with confidence.
Every PR, in business terms
These PRs are under review by the maintainers and have not been merged yet. Click one to see the problem, the proposal and the expected value.
-
#1984opened Oct 11, 2026Under review Android class search that works on large app packages REA's Android class search failed outright when the decompiler listed the same class more than once, which is common in large apps; the PR accepts the repetition and returns results without duplicates.
- The problem
- To examine an Android app, REA uses a decompiler that lists the package's classes page by page. In large apps split into several code files that bundle popular libraries, that list contains repeated class names. REA treated any repetition as an inconsistent inventory, and class search returned "unreadable output", making class discovery unusable on those apps.
- What the PR proposes
- The proposed fix keeps the check that every loaded class was read, but stops rejecting repeated names and removes duplicates from the results before filtering by the query. A new test simulates an inventory with a repeated class, fails on the current version and checks that the total and the results come out right.
- Expected value
- With the change, anyone investigating large Android apps with REA can search classes again, and the result still verifies that nothing was left out.
-
#1983opened Oct 11, 2026Under review REA setup for Hermes works with an empty config file The command that connects REA to the Hermes agent failed when Hermes's config file existed but was empty, a common first-run state; the PR treats it like a new file.
- The problem
- REA's setup command registers the tool in the configuration of each supported AI agent. For Hermes, an empty config file, a common state right after the first run, was read as malformed configuration and setup ended in failure. Uninstall, update maintenance and the shared configuration reader rejected the same file.
- What the PR proposes
- The proposed fix applies the empty-file rule, which already covered agents configured in JSON, before reading the Hermes file, so it is configured as if it did not exist. Other formats behave as before, and new tests configure empty and newline-only files and check what gets written.
- Expected value
- With the change, anyone setting REA up for Hermes completes the configuration on the first try, as already happened when the file did not exist.
-
#1982opened Oct 11, 2026Under review Universal Mac apps read without a false integrity error When opening universal Mac apps, which hold Intel and Apple Silicon builds in one file, REA could report an integrity error that did not exist; the PR makes it read the Intel part correctly.
- The problem
- Universal Mac apps bundle an Intel build and an Apple Silicon build in a single file. When the Intel part carries a capability flag that is common in these executables, REA misread the description printed by Apple's tool, could not find the matching part in the file and reported an integrity failure. The case was observed with Sublime Text on macOS 26.
- What the PR proposes
- The proposed fix reads the capability flag Apple's tool prints, whether named or in hexadecimal, and when the flag is missing it matches the parts by name, processor type, position and size. New tests cover the flag formats and a universal file whose read fails on the current version.
- Expected value
- With the change, anyone analyzing Mac apps with REA gets both builds of the program listed instead of a false alarm about a corrupted file.
-
#1981opened Oct 11, 2026Under review Valid WebAssembly modules analyzed instead of rejected REA's WebAssembly analysis rejects a valid module when one of its section names contains a null character; the PR makes it analyze the module normally.
- The problem
- REA uses a set of external tools to examine WebAssembly modules and checks what one of them displays against what another decodes. When the name of a custom section contains a null character, which the format allows, the display cuts the name at that point and the comparison fails. The module, which is valid, comes back as "unreadable output" instead of producing the evidence report.
- What the PR proposes
- The proposed fix compares the displayed line with the decoded name only up to the first null character, the same rule the project already applies to module names since PR #1967. The other format, count and position checks on sections still apply, and a new test covers the case while still rejecting names that differ before the null character.
- Expected value
- With the change, anyone analyzing a WebAssembly binary with this kind of name gets the evidence report instead of an error, without opening a gap: a forged name still cannot pass for another one.
-
#1925opened Oct 11, 2026Under review Invalid file paths rejected at the point of entry The PR makes the binary analysis tools reject file paths containing a character no operating system accepts as soon as they arrive, with a clear error.
- The problem
- REA takes requests from AI agents to analyze files. The tools that examine Windows executables, Linux binaries and crash recordings, WebAssembly modules and Ethereum smart contracts accept paths containing a null character, which no operating system allows in file names. The request passes the input check and only fails further in, at the disk or in external programs, with generic messages or ones that miss the real cause.
- What the PR proposes
- The proposed fix applies to these tools the same input rule other REA tools already follow: a path with a null character is turned away on arrival, with a clear message naming the offending field. The PR extends the input-rule tests to every changed field, and independent testing during review showed responses identical to before for valid paths.
- Expected value
- With the change, the AI agent gets an error it can understand and fix, and no disk access or external program is ever triggered with such a path. Nothing changes for anyone using valid paths.
Figures updated on Oct 11, 2026.
The same care in your system
The habits behind these PRs carry over to backends that move money: reproduce the problem before fixing it, prove the fix with a test and keep sensitive data from leaking.