Atlas / MCP servers / morluto / Reverse Engineer Anything

Reverse Engineer AnythingBLOCK

mcp/morluto/reverse-engineer-anything

Reverse engineer anything with agents, from app behavior down to native binaries.

Verdict
BLOCK
Grade
D
Trust score
61 /100
Exposed tools
17 16r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
8,470
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English · 简体中文 · 日本語 · 한국어 · العربية

One MCP for reverse engineering across binaries, applications, and runtime behavior.

See a feature you like. Understand how it works, down to the binary level.

[](https://www.npmjs.com/package/rea-agents) [](https://github.com/morluto/rea/actions/workflows/ci.yml) [](#tool-catalog-for-investigation) [](https://nodejs.org/) [](LICENSE) [](https://discord.gg/GkcryMnJDM)

Quick start · Current status · Investigation model · Tool catalog · Roadmap · How it works

npx rea-agents setup

Read from source at commit e6d8b0ffce2bOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add rea-agents -- npx -y [email protected] mcp
03

Exposed tools (17)

16 read · 1 write · 0 destructive.

ToolRiskDescription
address_to_file_offsetreadMap one provider-normalized virtual address to its original nonnegative file offset. Unmapped addresses fail explicitly, and providers without an authoritative mapping API return typed capability unavailability.
audit_residual_unknownsreadReview current residual-unknown heads against retained evidence, revision integrity, and declared authority without silently closing unanswered questions.
beyond_frame_limit_toolreadRegistered in an in-scope frame after index 999
child_toolreadMust be removed after child navigation
compare_application_versionsreadCompare two shipped application artifacts through complete inventory and optional static or runtime evidence without equating missing data with unchanged behavior.
escaped_child_toolreadcross-origin-child-secret
investigate_featurereadTrace a feature through relevant artifact, symbol, and function evidence while distinguishing observations, inferences, and residual unknowns.
lookup-userreadUntrusted page declaration
prepare_bounded_process_capturereadChoose a command, inputs, observations, and stopping conditions for a process capture that answers the behavioral question.
private_toolreadprivate-tool-secret
provider_neutral_fixturereadFixture contract for provider-neutral output validation.
read_bytesreadRead analyzed bytes from one provider-normalized virtual address. The hexadecimal payload reports the exact returned length; incomplete reads remain explicit and unsupported provider APIs return typed capability unavailability.
search_ordersreadSearch orders; authorization=Bearer tool-secret
test-fixturereadA test conformance fixture
trace_crashreadCorrelate a crash symptom with static call and reference evidence plus optional process capture observations.
update_orderwriteUpdate an order
verify_reconstructionreadEvaluate a finite reconstruction specification against retained Evidence comparisons without broadening pass results into global equivalence claims.
04

Trust audit

BLOCKgrade D · trust 61/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (4 observation(s))
Shell
declared (10 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build-conformance-fixtures.mjs:152
const swiftVersion = firstLine((await exec(swiftc, ["--version"])).stdout);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build-conformance-fixtures.mjs:196
await exec(compiler, input.arguments, { maxBuffer: 20 * 1024 * 1024 });
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build-conformance-fixtures.mjs:225
version: firstLine((await exec(compiler, ["--version"])).stdout),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build-conformance-fixtures.mjs:248
version: firstLine((await exec(compiler, ["--version"])).stdout),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/generate-completion-ledger.mjs:23
const { stdout } = await exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
scripts/fixtures/browser-verifier-site.mjs:106
body: JSON.stringify({ token: "request-body-secret-value", active: true })
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
scripts/fixtures/browser-verifier-site.mjs:109
socket.addEventListener("open", () => socket.send(JSON.stringify({ token: "websocket-secret-value" })));
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/ghidra/GhidraSessionError.test.ts:51
const token = "actual-bridge-authentication";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/boundary/mcp/ghidraFailureDiagnostics.test.ts:11
const token = "fixture-authentication-token";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/boundary/providers/ghidra/ghidraLauncher.test.ts:208
const token = "secret-token-that-must-not-leak";
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.jscpd.json
.jscpd.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxfmtrc.json
.oxfmtrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxlintrc.json
.oxlintrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/application/LinuxHopper.test.ts:233
file_hash: createHash("sha1").update(bytes).digest("hex"),
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/application/LinuxHopper.ts:339
createHash("sha1").update(bytes).digest("hex") === release.file_hash;
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/application/MacHopper.test.ts:38
: createHash("sha1").update(this.archive).digest("hex"),
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/application/MacHopper.ts:259
createHash("sha1").update(bytes).digest("hex") === release.file_hash;
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/dotnet/ManagedMetadataHeaps.ts:223
Buffer.from(createHash("sha1").update(publicKey).digest().subarray(-8))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/lib/android-cli-cancellation.mjs:6
} from "../../dist/process/ProcessOwnership.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/lib/browser-popup-e2e.mjs:11
import { PlaywrightBrowserScenarioProvider } from "../../dist/browser/PlaywrightBrowserScenarioProvider.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/lib/browser-popup-e2e.mjs:12
import { PlaywrightScenarioEvents } from "../../dist/browser/PlaywrightScenarioEvents.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/lib/browser-popup-e2e.mjs:13
import { BrowserScenarioSecrets } from "../../dist/browser/BrowserScenarioSecrets.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/lib/browser-popup-e2e.mjs:14
import { browserScenarioSchema } from "../../dist/domain/browserScenario.js";

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha e6d8b0ffce2bfull audit observations/trust-audit/mcp-server/morluto__reverse-engineer-anything.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06e6d8b0ffce2bBLOCKD61first audit
06

Questions

What is the Reverse Engineer Anything MCP server?

Reverse engineer anything with agents, from app behavior down to native binaries.

What tools does Reverse Engineer Anything expose?

17 in total: 16 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Reverse Engineer Anything safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (61/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Reverse Engineer Anything need?

It reads REA_BROWSER_VERIFIER_SECRET and XAUTHORITY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Reverse Engineer Anything run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as rea-readiness-javascript-cli at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (e6d8b0ffce2b), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement