Atlas / MCP servers / morluto / rea

reaBLOCK

mcp/morluto/rea

Reverse engineer anything with agents, from app behavior down to native binaries.

Verdict
BLOCK
Grade
F
Trust score
53 /100
Exposed tools
16 15r · 1w · 0d
Transport
stdio
License
MIT
Stars
418
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English · 简体中文 · 日本語 · 한국어 · العربية

Reverse engineer anything with agents, from app behavior down to native binaries.

See a feature you like. Understand how it works, down to the binary level.

[](https://www.npmjs.com/package/rea-agents) [](https://github.com/morluto/rea/actions/workflows/ci.yml) [](#tool-catalog-for-investigation) [](https://nodejs.org/) [](LICENSE)

Quick start · Current status · Investigation model · Tool catalog · Roadmap · How it works

npm install --global rea-agents && rea setup

See a feature in an app that you want in your own product? Give the app to your agent—even without its source code. With REA, the agent can investigate the feature, explain how it works, show its evidence, and build a version adapted to your stack and requirements.

REA gives agents one consistent way to investigate software. Today that includes deep native analysis and function dossiers through Hopper or bring-your-own Ghidra on Linux, plus an experimental Windows x64 Ghidra P0 for approved native PE applications; execution-free manage

Read from source at commit 53b1a75a2319OBSERVED · 2026-09-29
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add rea-agents -- npx -y [email protected] mcp
03

Exposed tools (16)

15 read · 1 write · 0 destructive.

ToolRiskDescription
address_to_file_offsetreadMap one provider-normalized virtual address to its original nonnegative file offset. Unmapped addresses fail explicitly, and providers without an authoritative mapping API return typed capability unavailability.
audit_residual_unknownsreadReview current residual-unknown heads against retained evidence, revision integrity, and declared authority without silently closing unanswered questions.
child_toolreadMust be removed after child navigation
compare_application_versionsreadCompare two shipped application artifacts through complete inventory and optional static or runtime evidence without equating missing data with unchanged behavior.
escaped_child_toolreadcross-origin-child-secret
investigate_featurereadTrace one feature from artifact and symbol discovery into bounded function evidence while preserving observations, inferences, and residual unknowns.
lookup-userreadUntrusted page declaration
prepare_bounded_process_capturereadDesign an approval-gated process capture scenario with exact executable, filesystem, environment, network, replay, timeout, and cleanup boundaries.
private_toolreadprivate-tool-secret
provider_neutral_fixturereadFixture contract for provider-neutral output validation.
read_bytesreadRead analyzed bytes from one provider-normalized virtual address. The hexadecimal payload reports the exact returned length; incomplete reads remain explicit and unsupported provider APIs return typed capability unavailability.
search_ordersreadSearch orders; authorization=[REDACTED]
test-fixturereadA test conformance fixture
trace_crashreadCorrelate a crash symptom with bounded static call and reference evidence plus optional approved process capture observations.
update_orderwriteUpdate an order
verify_reconstructionreadEvaluate a finite reconstruction specification against retained Evidence comparisons without broadening pass results into global equivalence claims.
04

Trust audit

BLOCKgrade F · trust 53/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (2 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build-conformance-fixtures.mjs:152
const swiftVersion = firstLine((await exec(swiftc, ["--version"])).stdout);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build-conformance-fixtures.mjs:196
await exec(compiler, input.arguments, { maxBuffer: 20 * 1024 * 1024 });
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build-conformance-fixtures.mjs:225
version: firstLine((await exec(compiler, ["--version"])).stdout),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build-conformance-fixtures.mjs:248
version: firstLine((await exec(compiler, ["--version"])).stdout),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/generate-completion-ledger.mjs:23
const { stdout } = await exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/domain/referenceSourceClassification.ts:284
"id_rsa",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/domain/referenceSourceClassification.ts:285
"id_ed25519",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/domain/referenceSourceClassification.ts:287
".netrc",
Why it matters. touches a credential store
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
scripts/fixtures/browser-verifier-site.mjs:91
body: JSON.stringify({ token: "request-body-secret-value", active: true })
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
scripts/fixtures/browser-verifier-site.mjs:94
socket.addEventListener("open", () => socket.send(JSON.stringify({ token: "websocket-secret-value" })));
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/boundary/providers/ghidra/ghidraLauncher.test.ts:151
const token = "secret-token-that-must-not-leak";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/fixtures/fakeCdpBrowserResults.ts:94
result: { ok: true, token: "response-body-secret" },
LOWInventory / provenance · inv.hidden_file · CWE-1104
.jscpd.json
.jscpd.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxlintrc.json
.oxlintrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/application/LinuxHopper.test.ts:233
file_hash: createHash("sha1").update(bytes).digest("hex"),
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/application/LinuxHopper.ts:329
createHash("sha1").update(bytes).digest("hex") === release.file_hash;
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/application/MacHopper.test.ts:38
: createHash("sha1").update(this.archive).digest("hex"),
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/application/MacHopper.ts:248
createHash("sha1").update(bytes).digest("hex") === release.file_hash;
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/dotnet/ManagedMetadataHeaps.ts:222
Buffer.from(createHash("sha1").update(publicKey).digest().subarray(-8))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/lib/browser-scenario-verifier.mjs:7
import { browserScenarioSchema } from "../../dist/domain/browserScenario.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/lib/managed-completion-report.mjs:1
import { createEvidence } from "../../dist/domain/evidence.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/lib/managed-conformance-manifest.mjs:4
import { parseBinaryTarget } from "../../dist/application/BinaryTargetResolver.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/lib/managed-conformance-manifest.mjs:5
import { inspectManagedArtifactBytes } from "../../dist/dotnet/ManagedArtifactInspector.js";

Gates applied: no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha 53b1a75a2319full audit observations/trust-audit/mcp-server/morluto__rea.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2953b1a75a2319BLOCKF53first audit
06

Questions

What is the rea MCP server?

Reverse engineer anything with agents, from app behavior down to native binaries.

What tools does rea expose?

16 in total: 15 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is rea safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (53/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does rea need?

It reads SECRET and XAUTHORITY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does rea run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as rea-readiness-javascript-cli at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (53b1a75a2319), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement