rea.run

2026-10-10

Agent reverse engineering with MCP

Agent reverse engineering means a coding agent (Cursor, Codex, Claude Code, Gemini CLI, Windsurf, Grok Build, and other MCP clients) calls local tools to inspect software, then writes explanations, diffs, or reconstruction notes for a human reviewer.

MCP (Model Context Protocol) is the connector: the agent does not invent a private RE API — it launches a registered stdio server such as npx -y rea-agents@latest mcp and uses the tools that server advertises.

Good practice. Give absolute paths, ask specific questions, require evidence (addresses, snippets, unresolved edges), and keep write/send actions behind approval. REA’s design emphasizes returning Evidence records and marking unknowns — treat those unknowns as work for you, not as permission to guess.

Boundaries. Authorized targets only. Do not use agent RE to pirate software, strip licenses, or evade DRM. Prefer your own builds, open-source binaries under compatible licenses, or samples you have written permission to analyze.

Next steps. /docs/install/, what is REA, Ghidra MCP, comparisons under /compare/.