Blog Network

morluto · 2026-10-08 · major

REA 6 — the agent reverse-engineering kit adds EVM, ELF crash and LLDB tools

REA 6.0 adds offline EVM bytecode inspection, ELF and crash analysis with pwntools and pwndbg, LLDB call tracing and Windows x86 support in Ghidra. Versions 5.0 to 6.3 shipped in three days as the repo passed 58,000 GitHub stars.

GitHub social card for the morluto/rea repository

Three major versions in four days: REA now reads smart contracts, Linux crashes and live macOS calls for your coding agent.

Key specs

GitHub stars58,879

Quick facts

Version6.0.0 (Oct 8), now 6.3.0 (Oct 9)
New in 6.0EVM bytecode, ELF layout and crashes, LLDB call tracing, Windows x86 PE
Breaking in 6.0MCP file inputs must be absolute host paths
LicenseMIT
Installnpx rea-agents@latest setup

What is it?

REA 6.0, released on October 8, 2026, adds offline EVM bytecode inspection through EVMole, offline ELF layout inspection through pwntools, recorded-crash inspection through pwntools and pwndbg, function and Objective-C call observation under LLDB, and native x86 PE support in Ghidra on Windows. REA (Reverse Engineer Anything) is an open-source CLI and MCP server that lets coding agents study software they have no source code for.

How does it work?

An agent calls REA's tools over MCP, and each answer comes back as an Evidence bundle tied to the analysed artifact. The 6.0 contract change means every caller-supplied file input — targets, snapshots, firmware and browser launch paths — must now be an absolute host path, so './app' becomes '/home/analyst/app'. Follow-up releases 6.1 to 6.3 on October 9 added Grok Build and OMP agent registration, changed MCP results to canonical Evidence and tightened capture rules.

Why does it matter?

REA started with app bundles and JavaScript; with 5.0 and 6.0 it now covers Android inventories, Ethereum contracts, Linux crash dumps and runtime tracing on macOS, so one agent workflow reaches far more of a security researcher's targets. The pace has a cost: 5.0, 6.0, 6.1, 6.2 and 6.3 each carry breaking changes, so scripts built on 4.x need the migration guides. The project is the top repository on GitHub trending today.

Who is it for?

security researchers and developers studying closed-source apps and binaries

Frequently asked questions

What breaks when upgrading REA from 4.x to 6.x?
REA 5.0 preserves incomplete native UI captures and requires JDK 17+ for Android analysis. REA 6.0 requires absolute host paths for MCP filesystem inputs. REA 6.1 removes set_current_document, 6.2 switches MCP results to canonical Evidence and removes legacy v3 process captures, and 6.3 removes truncated_scopes and changes browser schema fields.
What did REA 5.0 add?
REA 5.0, released October 7, 2026, added macOS bundle anatomy to application graphs, Android and Apple inventory graph tools, browser network and source-map tracing, Wakaru module recovery and support for iOS-style app bundles. Its breaking changes preserve incomplete native UI captures and require JDK 17 or newer for Android analysis.
Can REA analyse smart contracts?
Yes. REA 6.0 added offline inspection of EVM bytecode interfaces through EVMole, so an agent can examine a compiled Ethereum contract's interface without its source code. The analysis runs offline on bytecode the user provides, like REA's other native inspection tools.
Which coding agents can REA register itself with?
REA's setup command registers its MCP server with many coding agents, including Claude Code, Cursor, Codex and Gemini CLI. Recent releases widened the list: 4.1 added Command Code, 6.1 added Grok Build and Grok Bot, and 6.3 added OMP registration during setup.

Try it

npx rea-agents@latest setup

Sources · 2 outlets

Tags

  • rea
  • reverse-engineering
  • mcp
  • agents
  • ghidra
  • lldb
  • pwntools
  • evm
  • security
  • open-source
  • github-trending

← All releases