Set up REA.

Connect REA to your coding agent, or inspect a local app from your terminal.

You'll need Node.js 22 (22.19+), 24 (24.11+) or 26+. npm comes with Node.js.

Don't have Node.js, or not sure?

Open a terminal and check:

Terminal
node -v
npm -v

If node -v prints v22.19+, v24.11+ or v26+, you're ready. If it prints an older version or "not recognized" / "command not found", install Node.js 24 LTS:

Windows (PowerShell)

Windows PowerShell
winget install OpenJS.NodeJS.LTS

Type Y if asked to accept the terms. Close PowerShell, open it again, then run node -v.

If PowerShell later says "running scripts is disabled on this system" when you run npx, run this once and try again:

Windows PowerShell
Set-ExecutionPolicy -Scope CurrentUser RemoteSigned

macOS

If you use Homebrew:

macOS · Homebrew
brew install node

Otherwise:

macOS
curl -fsSL https://fnm.vercel.app/install | bash

Close Terminal, open it again, then:

macOS
fnm install 24
fnm default 24

Linux

Linux
curl -fsSL https://fnm.vercel.app/install | bash

The installer needs curl and unzip (on Debian/Ubuntu: sudo apt install curl unzip). Close the terminal, open it again, then:

Linux
fnm install 24
fnm default 24

Your distribution's own nodejs package is often older than 22.19, so check node -v if you use it instead.

Prefer a regular installer? Download the LTS version from nodejs.org.

Connect your coding agent

Run setup to connect REA to your coding agent. Client choices include Claude Code, Codex, Cursor, Gemini CLI, Windsurf, Grok Build, and other supported MCP clients. Grok Bot's connector is added from its chat.

New to coding agents?

A coding agent is an AI assistant that works on your computer instead of in a browser tab. It can read files and run commands, and it asks before making changes. REA gives it reverse-engineering tools.

If you don't have one yet, pick one, follow its install page and sign in:

  • Claude Code by Anthropic. Needs a paid Claude plan.
  • Codex by OpenAI. Sign in with your ChatGPT account.
  • OpenCode, open source. Connect the model provider of your choice.

Then open it and copy the prompt below into it. The agent runs REA's setup and shows you the plan before changing anything.

Your coding agent

Install REA and connect it to this coding agent using npx rea-agents@latest setup. Show me the setup plan for approval, then verify the installation.

Or run setup yourself
How do I open a terminal?
  • Windows: open the Start menu, type PowerShell and press Enter.
  • macOS: press ⌘ Space, type Terminal and press Enter.
  • Linux: press Ctrl Alt T on most desktops.

Paste a command with Ctrl V (macOS: ⌘ V; Linux terminals: Ctrl Shift V), then press Enter.

Terminal
npx rea-agents@latest setup

Choose your client and review the setup plan. REA adds its MCP connection and the matching investigation skill, keeping a backup of existing configuration. It asks before applying the changes.

Restart your client when setup finishes.

How do I restart my client?

Desktop apps (Claude Desktop, Cursor, Windsurf, VS Code): quit the app completely, then open it again. Closing the window isn't enough. On macOS press ⌘ Q; on Windows, also quit from the tray icon if there is one.

Terminal agents (Claude Code, Codex, Gemini CLI): exit the session and start it again.

Give your agent a target path and a specific question. For a JavaScript or Electron app, you might start with:

Look at /absolute/path/to/app and find how it exports data. Show the entry points, calls and dependencies involved, with the source locations for your findings.

Replace the path with your local target.

How do I get a folder's full path?
  • Windows: in File Explorer, right-click the folder and choose Copy as path. On Windows 10, hold Shift while right-clicking.
  • macOS: in Finder, right-click the folder, hold Option and choose Copy "…" as Pathname.
  • Any system: drag the folder into a terminal window and its path appears.

In a terminal, put quotes around a path that contains spaces.

Use the CLI

Analyze a JavaScript or Electron application folder or ASAR archive without running the app:

Static application analysis
npx -y rea-agents@latest analyze-javascript-application \
  /absolute/path/to/app --json

Replace the path with your extracted app directory or .asar file. On Windows, a path such as "D:/apps/example" works here.

Where do I find an app's .asar file?

Electron apps usually keep it in a resources folder:

  • Windows: C:\Users\<you>\AppData\Local\Programs\<App>\resources\app.asar
  • macOS: /Applications/<App>.app/Contents/Resources/app.asar (right-click the app and choose Show Package Contents)
  • Linux: often /opt/<App>/resources/app.asar

Some apps install elsewhere. Search the app's folder for app.asar.

The result identifies the app, shows connections between modules and gives their source locations. Connections REA cannot resolve are marked in the result.

If you'd like a permanent rea command in your shell:

Install the CLI
npm install --global rea-agents

Continue with the JavaScript application guide

Set up native analysis

Native binaries need a local analysis tool. Choose and configure one below, then give REA your executable or library.

Choose a tool: Ghidra, Hopper or IDA

Ghidra

Use an existing Ghidra 12.1.x installation and a 64-bit JDK 21 or newer on Linux or macOS, on x64 or arm64. Your Ghidra installation needs a native decompiler for your host architecture. Set the paths before running setup:

Connect your Ghidra installation
Ghidra connection · macOS / Linux
export GHIDRA_INSTALL_DIR=/absolute/path/to/ghidra_12.1.4_PUBLIC
export JAVA_HOME=/absolute/path/to/jdk-21
npx -y rea-agents@latest doctor --provider ghidra --json
npx rea-agents@latest setup

Replace both paths with your existing installations. Setup checks them and records valid settings for your selected client. On Linux arm64, you may need to build Ghidra's native decompiler separately.

Connect Ghidra on Windows

Windows x64 has experimental, read-only support for native x86 and x64 PE applications and DLLs on fixed local NTFS drives. Use an existing Ghidra 12.1.x installation and a 64-bit JDK 21 or newer:

Ghidra connection · Windows PowerShell
$env:GHIDRA_INSTALL_DIR = "C:/tools/ghidra_12.1.4_PUBLIC"
$env:JAVA_HOME = "C:/tools/jdk-21"
npx -y rea-agents@latest doctor --provider ghidra --json
npx rea-agents@latest setup

Replace the two paths with your installations, then review setup's plan.

Hopper

Connect Hopper on macOS or Linux. Run the setup command above; it detects an existing installation or offers an installation plan for your approval.

On macOS, complete Hopper's first-run choice of demo mode or license activation before an unattended analysis.

IDA

The verified IDA setups use Windows, with an existing MCP registration for an attached GUI or a headless database. Linux and macOS headless analysis remains unverified.

Connect an existing IDA MCP registration

Keep the upstream server's working command, args and optional env in a JSON file. An existing mcpServers object with an ida-pro-mcp entry is also accepted. Point REA at that file before setup:

IDA connection · Windows PowerShell
$env:REA_IDA_MCP_CONFIG = "C:/analysis/ida-mcp.json"
$env:REA_ANALYSIS_PROVIDER = "ida"
npx -y rea-agents@latest doctor --provider ida --json
npx rea-agents@latest setup

The attached profile uses upstream legacy 1.4.0 tools with the original binary already open in IDA. The headless profile uses the upstream database-supervisor API and a registration with "mode": "headless"; real verification covers an IDA 9.3 Windows x64 supervisor. Doctor checks the registration without starting IDA.

Give REA the original executable path, with --provider ida in a CLI query. For an agent, include REA_IDA_MCP_CONFIG in the REA registration's environment and select IDA when opening the binary.

For an existing Ghidra setup, inspect a function with:

Function analysis
npx -y rea-agents@latest function /absolute/path/to/program main \
  --provider ghidra --json

Replace main with the function name or address you want to inspect.

How native analysis sessions work

Each CLI command imports and analyzes the binary, then closes its session. Your agent's MCP queries reuse the imported binary while that session is open.

Follow a native analysis example to see how the function result leads to a recovered calculation.

Getting help

If your agent doesn't see REA

Restart or reconnect the client after setup. Check its REA connection with doctor; for Codex:

Check one client
npx -y rea-agents@latest doctor --client codex --json

If a provider needs attention

Check the provider you're using. For Ghidra:

Check one provider
npx -y rea-agents@latest doctor --provider ghidra --json

The report gives the failed check and a suggested next step.

Top