reaBLOCK
Reverse engineer anything with agents, from app behavior down to native binaries.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English · 简体中文 · 日本語 · 한국어 · العربية
Reverse engineer anything with agents, from app behavior down to native binaries.
See a feature you like. Understand how it works, down to the binary level.
[](https://www.npmjs.com/package/rea-agents) [](https://github.com/morluto/rea/actions/workflows/ci.yml) [](#tool-catalog-for-investigation) [](https://nodejs.org/) [](LICENSE)
Quick start · Current status · Investigation model · Tool catalog · Roadmap · How it works
npm install --global rea-agents && rea setup
See a feature in an app that you want in your own product? Give the app to your agent—even without its source code. With REA, the agent can investigate the feature, explain how it works, show its evidence, and build a version adapted to your stack and requirements.
REA gives agents one consistent way to investigate software. Today that includes deep native analysis and function dossiers through Hopper or bring-your-own Ghidra on Linux, plus an experimental Windows x64 Ghidra P0 for approved native PE applications; execution-free manage
53b1a75a2319OBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add rea-agents -- npx -y [email protected] mcp
Exposed tools (16)
15 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
address_to_file_offset | read | Map one provider-normalized virtual address to its original nonnegative file offset. Unmapped addresses fail explicitly, and providers without an authoritative mapping API return typed capability unavailability. |
audit_residual_unknowns | read | Review current residual-unknown heads against retained evidence, revision integrity, and declared authority without silently closing unanswered questions. |
child_tool | read | Must be removed after child navigation |
compare_application_versions | read | Compare two shipped application artifacts through complete inventory and optional static or runtime evidence without equating missing data with unchanged behavior. |
escaped_child_tool | read | cross-origin-child-secret |
investigate_feature | read | Trace one feature from artifact and symbol discovery into bounded function evidence while preserving observations, inferences, and residual unknowns. |
lookup-user | read | Untrusted page declaration |
prepare_bounded_process_capture | read | Design an approval-gated process capture scenario with exact executable, filesystem, environment, network, replay, timeout, and cleanup boundaries. |
private_tool | read | private-tool-secret |
provider_neutral_fixture | read | Fixture contract for provider-neutral output validation. |
read_bytes | read | Read analyzed bytes from one provider-normalized virtual address. The hexadecimal payload reports the exact returned length; incomplete reads remain explicit and unsupported provider APIs return typed capability unavailability. |
search_orders | read | Search orders; authorization=[REDACTED] |
test-fixture | read | A test conformance fixture |
trace_crash | read | Correlate a crash symptom with bounded static call and reference evidence plus optional approved process capture observations. |
update_order | write | Update an order |
verify_reconstruction | read | Evaluate a finite reconstruction specification against retained Evidence comparisons without broadening pass results into global equivalence claims. |
Trust audit
BLOCKgrade F · trust 53/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const swiftVersion = firstLine((await exec(swiftc, ["--version"])).stdout);
await exec(compiler, input.arguments, { maxBuffer: 20 * 1024 * 1024 });version: firstLine((await exec(compiler, ["--version"])).stdout),
version: firstLine((await exec(compiler, ["--version"])).stdout),
const { stdout } = await exec("id_rsa",
"id_ed25519",
".netrc",
body: JSON.stringify({ token: "request-body-secret-value", active: true })socket.addEventListener("open", () => socket.send(JSON.stringify({ token: "websocket-secret-value" })));const token = "secret-token-that-must-not-leak";
result: { ok: true, token: "response-body-secret" },.jscpd.json
.oxlintrc.json
.prettierignore
.release-please-manifest.json
file_hash: createHash("sha1").update(bytes).digest("hex"),createHash("sha1").update(bytes).digest("hex") === release.file_hash;: createHash("sha1").update(this.archive).digest("hex"),createHash("sha1").update(bytes).digest("hex") === release.file_hash;Buffer.from(createHash("sha1").update(publicKey).digest().subarray(-8))import { browserScenarioSchema } from "../../dist/domain/browserScenario.js";import { createEvidence } from "../../dist/domain/evidence.js";import { parseBinaryTarget } from "../../dist/application/BinaryTargetResolver.js";import { inspectManagedArtifactBytes } from "../../dist/dotnet/ManagedArtifactInspector.js";Gates applied: no_behavioural_pass.
53b1a75a2319full audit observations/trust-audit/mcp-server/morluto__rea.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 53b1a75a2319 | BLOCK | F | 53 | first audit |
Questions
What is the rea MCP server?
Reverse engineer anything with agents, from app behavior down to native binaries.
What tools does rea expose?
16 in total: 15 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is rea safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (53/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does rea need?
It reads SECRET and XAUTHORITY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does rea run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as rea-readiness-javascript-cli at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (53b1a75a2319), read on 2026-09-29. The repository is watched and re-audited when it changes.