REA: The Repo Teaching AI Agents to Reverse-Engineer Any App
An open-source MCP tool lets coding agents crack open compiled binaries with no source code, and Rob Shocks tests it against his own encrypted app to see if the hype holds up.
Posted
yesterday
Duration
Format
Demo
educational
Views
66.1K
1.3K likes
57 · 43
Big Idea
The argument in one line.
REA doesn't invent new reverse-engineering power, it removes the friction between a coding agent and professional tools like Ghidra and IDA Pro, so any app you ship as a compiled binary should now be assumed readable by someone else's AI agent.
Who This Is For
Read if. Skip if.
READ IF YOU ARE…
You ship a desktop app, browser extension, mobile app, or heavy client-side JavaScript bundle and want to know what's actually inspectable now.
You're a developer curious how AI agents can decompile and explain compiled binaries without access to the source.
You've lost the source to one of your own old builds and want to understand how to recover the logic.
SKIP IF…
You want a full install walkthrough, this is an overview plus a live test, not a step-by-step tutorial.
You're after legal advice on reverse engineering, Rob says plainly he isn't a lawyer.
TL;DR
The full version, fast.
REA is an open-source MCP server and CLI that lets a coding agent inspect a compiled app it has no source code for, trace how a feature works, and hand back pseudocode and evidence instead of the original source. It isn't a new decompiler, it wraps proven tools like Ghidra, Hopper, and IDA Pro and removes the expertise barrier that used to protect closed-source software. Rob tests it against his own stripped binary and watches it recover the unlock logic and generate working code without ever seeing the source. The takeaway: the time and skill reverse engineering used to require was the real moat, not the compiled code itself, so what you ship now needs a different kind of protection, and running REA against anything you don't own should happen in a sandbox.
Free for members
Chat with this breakdown — free.
Sign in and you get 23 free chat messages on us — ask for the hook, quote a framework, find the exact transcript moment, generate a markdown action plan. Bring your own key when you want unlimited.
Rob opens with the hook: REA lets a coding agent reverse-engineer apps it has no source for, and it's pulling thousands of GitHub stars a day.
01:04 – 02:15
02 · What REA actually is (and isn't)
You show your agent a feature you want in your own product, it investigates the target app and explains how that feature is built, without needing the app's source code.
02:15 – 03:13
03 · How it works
REA runs as an MCP server and CLI on native binaries across Mac, Windows, and Linux, plus .NET, APKs, firmware, and smart contracts. It isn't a new decompiler, it wraps proven tools like Ghidra, Hopper, and IDA Pro and gives an agent plain-text tools on top. Setup is one command that asks before touching anything critical.
03:13 – 04:14
04 · Sponsor: TestSprite
A sponsored segment for TestSprite, an AI testing agent that writes and runs end-to-end tests against a real running app and hands failures back to the coding agent to fix.
04:14 – 05:59
05 · Demo: I hid a secret in my app. Can my agent find it?
Rob builds his own password-vault app with every function name stripped, to run a fair test with a real answer key. Pointed at the binary with Ghidra, REA pulls back 242+ unlabeled functions, decompiles them, and finds the unlock rule a handful of calls in.
05:59 – 07:25
06 · Closed source isn't a moat anymore
REA didn't copy the source, it understood the logic and wrote a brand-new code generator the app never had. For years the slowness and cost of reverse engineering was the real protection for shipped software, and that friction is now gone.
07:25 – 08:21
07 · The catch: legal, security, speed
Reverse engineering for interoperability is generally protected, but many apps' terms of service ban it outright. REA isn't a sandbox, so it runs with your real permissions, and the project is changing fast enough to need constant updates.
08:21 – 08:52
08 · What I'd actually use it for
Rob lists his own use cases: learning how well-built apps solve problems, auditing Electron apps already on his machine, and recovering logic from his own old builds.
08:52 – 09:09
09 · Outro
A soft pitch for Switch Dimension's waitlist and a subscribe ask.
Atomic Insights
Lines worth screenshotting.
REA is an MCP server and CLI that lets a coding agent reverse-engineer a compiled app it has no source code for, then explain how a feature works.
REA wraps existing professional reverse-engineering tools like Ghidra, Hopper, and IDA Pro rather than inventing new decompiling power.
What REA returns is pseudocode, assembly, module maps and evidence, never the original source code, because compiling destroys the original source for good.
REA covers native binaries on Mac, Windows, and Linux, plus .NET, Android APKs, firmware, websites, and smart contract bytecode, not just Electron apps.
In a controlled test, REA decompiled 242+ unlabeled functions from a stripped binary and wrote a working code generator without ever seeing the source.
REA didn't copy the tested app's source code, it understood the logic and generated a brand-new implementation the original app never had.
For decades, the time and expertise reverse engineering required was the real protection for shipped software, not a technical barrier, and that friction is now gone.
Running REA against an untrusted binary executes with your real system permissions, since the tool provides no sandbox by default.
Reverse engineering for interoperability has generally been legally protected, but many apps' terms of service explicitly ban it, and breaking DRM is a separate legal problem.
If your moat was ever just that your code was compiled and hidden, that protection is gone, your real moat is data, users, security, shipping speed, and taste.
Takeaway
What REA means if you ship compiled software
WHAT TO LEARN
REA doesn't add new reverse-engineering power, it strips away the friction between a coding agent and professional tools, so any compiled app you ship should now be treated as readable.
02What REA actually is (and isn't)
REA lets your coding agent investigate a feature in an app it has no source code for and explain how that feature works, without ever handing back the original source.
What comes back is pseudocode, assembly, module maps, call paths and network activity, each with evidence showing where it came from and how confident the model is.
It runs as an MCP server and CLI, so it plugs into Claude Code, Cursor, Codex, or anything else that speaks MCP.
It covers native binaries on Mac, Windows, and Linux, not just Electron apps, plus .NET, Android APKs, firmware, websites and smart contract bytecode.
03How it works
REA isn't a new decompiler, it wraps proven reverse-engineering tools professionals already use: free Ghidra from the NSA, Hopper on Mac, and the paid industry-standard IDA Pro.
What changed isn't capability, it's friction: REA gives an agent dozens of plain-text tools on top of tools that used to require specialist skill to operate.
Setup is one command, npx rea-agent@latest setup, which shows a plan, backs up your config, and asks before touching anything critical.
05Demo: I hid a secret in my app. Can my agent find it?
Before testing on a real target, build your own app with a real source-code answer key and every function name stripped, mirroring how real shipped apps compile.
Pointed at a stripped binary with Ghidra, REA pulled back 242+ unlabeled functions and decompiled machine code into C-like pseudocode on its own.
Running REA against a binary you don't control executes with your real system permissions by default, with no sandbox, so an unfamiliar binary could carry a prompt injection aimed at your agent.
06Closed source isn't a moat anymore
REA didn't copy the tested app's source code, it understood the logic and generated an entirely new implementation the app never had.
For years, the slowness and expense of reverse engineering was the real protection for shipped software, not any technical barrier, and that friction is now gone.
If you ship a desktop app, browser extension, game, mobile app, or heavy client-side JS bundle, assume any agent can now map out how it works.
Your actual moat shifts to what can't be read from a compiled binary: your data, your users, your cloud security, how fast you ship, and your taste.
07The catch: legal, security, speed
Reverse engineering for interoperability has generally been legally protected, but plenty of apps explicitly ban it in their terms of service, and breaking DRM is a separate legal problem.
Keep your agent's approval prompts switched on while using tools like this, since an unfamiliar binary could carry a prompt injection aimed at your agent.
The project is moving fast with frequent breaking changes, so treat any setup as temporary and plan to update constantly.
08What I'd actually use it for
Study how well-built apps solve problems like offline sync, clipboard handling, and search, then build your own version informed by what you learn.
Recover logic from your own old builds when the original source has been lost, using the compiled binary as the only remaining record.
Don't use it to just clone a competitor's product, that's legally risky and misses the point, since distribution and execution matter more than code now.
Glossary
Terms worth knowing.
MCP (Model Context Protocol)
A standard that lets AI coding agents connect to external tools and servers, such as REA, so the agent can call their functions directly.
Decompile
Turning compiled machine code back into a readable approximation of the original source logic, without recovering the exact original code.
Ghidra
A free reverse-engineering tool released by the NSA that disassembles and decompiles software, one of the engines REA wraps.
Pseudocode
A simplified, readable approximation of a program's logic generated from decompiled machine code, not the literal original source.
Native binary
A compiled application built to run directly on an operating system such as Mac, Windows, or Linux, as opposed to one that ships its JavaScript source inside an Electron wrapper.
“Your moat really is in your data, your users, your cloud security, how fast you ship, your taste.”
concrete reframe of where defensibility actually lives→ newsletter pull-quote↗ Tweet quote
05:49
“It didn't copy the code. It understood the logic and then wrote something completely new.”
the key nuance that separates this from piracy→ TikTok hook↗ Tweet quote
04:13
“There could be hidden malicious instructions for your AI. Run this stuff in a sandbox.”
a high-stakes safety warning in one breath→ IG reel cold open↗ Tweet quote
The Script
Word for word.
Read-along
Don't just watch it. Burn it in.
See every word as it's spoken — crank it to 2× and still catch all of it. The same dual-channel trick behind Amazon's Kindle + Audible.
17px
okay so there's a new open source repo that lets your code agent that might be cloud code cursor codex whatever you use look inside an app that it has no source code for figure out how a feature works show you the evidence and then build you a version. People are doing this for games, for software, they're cracking desktop applications that have been closed source for the last 20 years.
So it's called OREA, which stands for reverse engineer anything. And it's one of the fastest rising repos on GitHub right now, something like seven or 8 ,000 stars in a single day and growing by the minute. I'm Rob from Switch Dimension, 20 years as a software developer and product manager.
And on this channel, we build real stuff with AI agents. And I want to do two things in this video. First, show you what React...
actually does because most of the posts that i'm seeing about this are getting it really wrong and second explain why i think it changes something really big for anyone who ships software and i'm going to actually show you working on some source code that i built and threw away the key to see if we can actually get it back again is this thing all hype or does it actually work so here's the pitch from the readme and it's basically this you see a feature in an app that you want in your own product you go and ask the agent to investigate it and it can do that without the actual source code of the app it's able to look inside and break it down Under the hood, it's basically an MCP server and a CLI, which you can easily plug into Cloud Code, Codex, Cursor, whatever you want.
Basically anything that speaks MCP, and that's a lot now. And this isn't just Electron apps where we could see some of the source code before. I'm talking about native binaries on Mac, Windows, and Linux.
This is a huge chunk of the desktop apps that you use every day. .NET, Android APKs, firmware, websites, even smart contract bytecode. Now here's where people are getting a little bit confused.
It doesn't just hand you the... original source code. Nothing can do that.
When an app is compiled, the original code is gone. What you're going to get back from this investigation is pseudo code, assembly, module maps, call paths and network activity with some evidence attached to show you why the agent thinks it's built this way. And the evidence gives you back is really interesting.
Every finding comes back with where it came from, how confident the model is and what it couldn't figure out itself. This is the kind of thing you would have spent an awful lot of money on and a huge amount of time to do previously. So the architecture is really simple.
So RIA itself isn't a decompiler. It's nothing... revolutionary or special.
It's basically wrapping the serious tools reverse engineers already use, which is things like Ghidra, which is free and from the NSA, Hopper on the Mac and IDA Pro, which is the expensive industry standard. So all of this reverse engineering was possible before with enough time and enough money. The difference now is the friction has been removed.
So these tools are all incredibly powerful and also notoriously hard to learn. What REA does is give your agent dozens of plain text. in 10 tools on top of them.
Things like open this binary, find the strings, follow the function colors so it can find its way through and understand the code. Setup is super simple. It's just npx rea -agent setup.
It shows you a plan of what it's going to change. It backs up your config, adds the MCP server and a skill that teaches your agent how to do the investigation. And then it asks before touching anything critical.
Coding agents often finish a session telling you everything is working great, but in reality, there are multiple issues. particularly when it hits production. This video is sponsored by longtime friends, Testbrite.
It's an AI testing agent that writes end -to -end tests and then runs them against your real running app. So an end -to -end test is exactly that, not just a simple test. It's actually impersonating a user to see if the app really works.
The bit I like is it plugs straight into your coding agent. There's an open source CLI and an MCP server. So in cloud code, I just say, hey, help me test the checkout flow.
It writes 12 tests. It runs them in a real... browser and in the cloud and i can set this up to run on a schedule maybe a test fails like the promo code isn't coming off the order total the failure comes back with the failing step it gives you a screenshot and the root cause so the agent fixes it then reruns and we get 12 out of 12 passing tests and those tests are kept so they run on every single change you can try it for free link in the description install the cli next time your agent finishes and says it's done and get test right to prove it now as always i'm totally holding my hands up here be so careful with this.
This is really powerful. You're going to be using this tool to inspect all these binaries and tools that you have no idea what's inside of. There could be hidden malicious instructions for your AI.
Run this stuff in a sandbox. Be very careful. OK, so let's actually use it.
And I wanted to do a fair test, not a kind of a, you know, trust me, bro, it worked. So I built my own app for this. I can't run this against an existing proprietary app out there or I will get sued.
So I just built my own one so you can see how this works. OK, so it's called a vault. You type in and unlock.
code and it either lets you in or it doesn't. Somewhere inside I've got a rule for what a valid code is and then this hidden message appears only when you get it right. Because it's my app there's no license key to worry about and I've got the perfect answer key the source code which I am now going to put away.
So I also built this the way a real app ships, which is optimized with every function name stripped out. So check unlock code is now just a function at this address, which is a lot more realistic. Now for the agent, I've got Ria set up in my agent here with Gither beside it, the free one from the NSA.
So it opens up the binary and it gets back 242 plus functions. Every one of them is just called fun and an address. And then it starts to decompile, turning machine code back into something a bit like the language C.
a handful of calls is actually found the one that matters so the big question does it actually work well it wrote me a little generator and gave me a code a g n t dash one zero zero one and I'm in. Big thing people are missing here is it's not pulling out the source code.
It's basically generating itself or breaking it down and reverse engineering it. It didn't copy the code. It understood the logic and then wrote something completely new, a code generator, which my app doesn't even have.
So I guess the big thing for software development for years, there's been this kind of unspoken protection. that software has been afforded. Sure, you could always reverse engineer app.
It's not that this wasn't possible before, but it was slow, specialized and really expensive. So almost nobody ever bothered doing it. That friction of reverse engineering was the protection and REAA and REAA basically deletes all that friction.
Now, I've seen a lot of people post about how planes are going to start falling out of the sky because they can be reverse engineered and hacked. I really don't think that is the case. There are still so many hurdles and layers that you need to get to before you can compromise many systems.
But in this world, if you ship a desktop app, a browser extension, a game, a mobile app, or a big client -side JavaScript bundle, you should now assume that anyone's agent can map out how it works. We're going to see some interesting GTA 6 mods coming up in the next few months.
And look, I don't think this is a disaster like so many people are saying on a lot of posts that I'm seeing. I just think it's a bit of a correction. Code was never really the moat in the first place.
Well, not for most of us anyway. Your moat really is in your data, your users, your cloud security, how fast you ship, your taste, and the stuff that runs on your... your servers where basically nobody else can inspect it.
Good security flip side to this, you can point this at apps on your own machine and ask, what is this thing actually doing? What is it sending home? There have been lots of cases where 3D printers and even coffee machines have been compromised and are sending tons of data off your network back to some source that you were not aware of.
Okay, so the important bits. Three things. One, legal.
I am not a lawyer. This isn't legal advice, but reverse engineering for interoperability has generally been protected. So it's something you're kind of allowed to do.
but a lot of apps have terms of service that exclusively ban it and breaking DRM or encryption is a whole separate legal problem. Your own apps, open source binaries, security challenges and things you're authorized to test are the safe ground. REA's own disclaimer says you are responsible.
Second thing is this isn't a sandbox. If you run a target through its runtime capture, it runs with your permissions. So don't point it at any random binary you downloaded off a forum and make sure you're keeping your agent's approval prompts switch on so you know what it's doing.
Who knows what kind of prompt injection could be in there. And the other thing is this repo seems to be moving extremely fast. Lots of breaking changes, amazing energy, but expected to change continuously.
So make sure you're updating it constantly. So as a software engineer, things that I would find this really useful for. So learning how great desktop apps handle things like offline sync, clipboards and search, and then go and build my own version.
I'd be using it to audit electron apps on my machine, which I have so many of now, and then recovering logic from my own bills where that source maybe has gone missing. What I wouldn't do is just point this at a competitor and clone the product. It's a legally risky thing to do and it misses the point.
What you want to do is understand the idea and build something better because you're never going to match that company's marketing anyway. And now it's all about distribution. So I'm curious, if you could point this at one feature in one app, what would it be?
So tell me in the comments. If you want to go deeper on building with agents, MCPs and things like this, that's exactly what we do in Switch Dimension, the course and community. It's closed at the moment.
The waitlist is open up and the link is in the description. And if this was useful, hit subscribe. I cover the agent tools that actually matter and skip the ones that don't.
Next, check this one out on skills.
The Hook
The bait, then the rug-pull.
A new open-source tool lets your coding agent crack open an app it has never seen the source for, explain how a feature works, and build you a version of it. It's called REA, and it's one of the fastest-rising repos on GitHub right now, pulling seven or eight thousand stars in a single day.
Frameworks
Named ideas worth stealing.
01:58model
REA investigation flow
Ask
Inspect & trace
Read the evidence
Use what you learn
The loop REA follows: your agent asks a question, REA inspects and traces the target binary, surfaces the evidence it found, and your agent uses what it learned to explain or implement the feature.
Steal fora mental model for any AI-agent-plus-external-tool investigation loop, not just reverse engineering
CTA Breakdown
How they asked for the click.
VERBAL ASK
08:21newsletter
“If you want to go deeper on building with agents, MCPs and things like this, that's exactly what we do in Switch Dimension, the course and community. It's closed at the moment, the waitlist is open.”
Soft pitch folded into the 'what I'd use it for' wrap-up rather than a hard sell, followed immediately by a plain subscribe ask.
Add Modern Creator as a preferred source and Google shows you more of our breakdowns in Search, Top Stories, and AI Overviews. It only changes what you see, and you can undo it in your Google settings anytime.
Add to Preferred SourcesOpens your Google source preferences with us pre-loaded. Tick the box and you're done.
Rob Shocks breaks down Anthropic's new AI-native SDLC playbook, the intent.md to plan.md artifact chain meant to keep agents and humans in sync from planning through autonomous maintenance.
A walkthrough of Lauren Tan's pstack: 21 engineering principles, 22 playbooks, and 24 skills that turn a coding agent from a slop machine into a verification-obsessed engineer.
Rob Shocks unpacks Andrej Karpathy's AI Ascent talk into four frameworks every builder needs in their head, then runs his own side-project folder through the test and kills three apps live.