Setup and updates
How do I install REA?
With Node.js and npm available, run setup, choose your coding agent and review the proposed changes.
npx rea-agents@latest setup
Setup registers REA's MCP connection and installs the matching investigation skill. Restart your agent when it finishes, then give it a target path and a question. Follow the setup guide for prerequisites and your first analysis.
Which coding agents can use REA?
Any agent that supports local MCP servers. Setup includes Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf, Devin, OpenCode, Antigravity, GitHub Copilot CLI, Command Code and VS Code.
How do I update REA?
REA releases frequently, including bug fixes. If you installed the CLI with npm:
rea update
Follow the setup refresh command printed by the update. If you
set up your agent through npx, run:
npx rea-agents@latest setup
Review the changes and restart your agent. Its REA connection
pins a package version, so refreshing setup makes it use the
new release. For one-off CLI commands, use
npx -y rea-agents@latest followed by the command.
Is installing the skill from skills.sh enough?
The skill gives your agent investigation instructions. Run REA setup to connect the MCP server and install the matching skill, then restart your agent so it can call the tools.
Analysis
What can I analyze with REA?
Start with the kind of software you have:
- Native executables and libraries: functions, assembly, pseudocode and references.
- JavaScript and Electron apps: modules, imports, IPC and source locations.
- Browser pages: scripts, requests and runtime observations.
REA also has workflows for managed assemblies, Android APKs, firmware and packaged resources. See the case studies for worked investigations.
Do I need Hopper, Ghidra or IDA?
Deep native analysis uses one of them. Static JavaScript and .NET inspection work with the supplied files and do not need a native analysis engine.
Connect your existing Ghidra or IDA installation, or let setup detect Hopper and propose an installation. Your host and target determine which provider can be used. Set up native analysis.
Can I use REA without a coding agent?
Yes. The CLI uses the same analysis workflows. For a local JavaScript or Electron app:
npx -y rea-agents@latest analyze-javascript-application \
/absolute/path/to/app --json
Replace the path with an extracted application folder or ASAR file. Use the CLI for installation options.
What code does REA return?
Native analysis returns assembly and pseudocode, with calls, references and relevant constants. JavaScript analysis returns modules, their relationships and source locations.
Your agent uses these findings to explain the behavior or write and test an implementation. The DX-Ball calculation and CTF flag checker show how that process works.
What should I ask my agent?
Give it a local target and one behavior to investigate. For a JavaScript or Electron app:
Use REA to analyze /absolute/path/to/app and explain how it exports data. Show the relevant code and source locations.
Replace the path with your target. The guides provide prompts for native, Electron and browser examples.
Troubleshooting
Why can't my agent see the REA tools?
Restart or reconnect your agent after setup. Check its REA
registration with doctor; for Codex:
npx -y rea-agents@latest doctor --client codex --json
Replace codex with your client ID, such as
claude_code or cursor. If the report
shows a missing or stale registration, run setup for that
client:
npx rea-agents@latest setup --client codex
Review its plan and restart the client. If registration is healthy but tools remain absent, check the client's MCP connection error. More setup diagnostics.
Do I need to start Hopper first?
REA starts Hopper when an operation needs it. On macOS, complete the first-run choice of demo mode or license activation before unattended analysis. See native provider setup.
What should I do if I hit a bug?
Update REA, restart your agent and retry the same task. A recent release may already fix the problem.
If it persists, open an issue with your REA version, operating system, target type, steps to reproduce and error output. Include the provider name when the problem involves native analysis.
Data and sharing
Does REA upload my app?
REA analyzes targets on your machine. Your agent receives the results, and its model provider's data policy applies to those results.
How can I share an example or contribute?
Have a useful REA example? We'd love to see it. Share the target, your question, the findings and how you checked them in an issue or pull request. Short code excerpts and figures help others follow the investigation.
Bug reports, feature requests, documentation and code improvements are welcome too. You can also discuss an example in the community.