REA Ships as an MIT-Licensed MCP Server and CLI With Three Deep-Binary Engines, and the Third One Merged 97 Minutes Before This Video Posted
Watch on TikTok
The artifact is a 28-second vertical MP4 at 720x1280, 30 fps, HEVC Main video at 210,156 bps paired with HE-AACv2 audio at 64,310 bps and 44,100 Hz, 281,035 bps overall, 1,008,215 bytes on disk, SDR, TikTok format id bytevc1_720p_281025-1, with a container duration that ffprobe measures at 28.70 seconds; the fps, abr, and asr fields in metadata.json are null, so those three numbers come from ffprobe rather than from TikTok. It posted on 2026-10-06 at 19:23:48 UTC from the handle @usama.khan.tech.ai under the channel nickname "Usama Khan | AI Fact Check", over the audio track "original sound - Usama Khan | AI Fact Check". At capture on 2026-10-07, one day after posting, the counters read 196 views, 6 likes, 5 saves, 0 comments, and 0 reposts. I read all 14 extracted frames and all 77 transcript words. Every frame carries a fixed top banner reading "FACT CHECK: REA". Frame 001 is a full-bleed shot of the presenter in a home studio, dark crewneck, boom-mounted dynamic microphone in the lower left, shelving behind him lit purple on the left and amber in the center, with the caption "AGENT". Frames 002 through 004 split the screen and put a dark card in the top half showing a README headline, "REA: Reverse Engineer Anything", above a grey attribution line reading "morluto/rea · README"; frame 002 draws an orange rectangle around the headline and captions "APP?", frame 003 drops the rectangle and captions "IT'S REAL", frame 004 captions "PLUGS INTO". Frame 005 clears the card to flat dark and captions "AND". Frame 006 is the densest screenshot in the video, a quote card with a blockquote glyph above highlighted text reading "REA supports Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf, Devin, OpenCode, Antigravity, GitHub Copilot CLI, and VS Code." attributed again to "morluto/rea · README", captioned "HAS LIMITS" with the word LIMITS in orange. Frames 007 and 008 return to a blank card over captions "ORIGINAL SOURCE" and "DECOMPILED CODE". Frames 009 through 012 hold one static card reading "DOS MZ analysis with Ghidra" while the captions run "ANALYSIS NEEDS", "A SEPARATELY", "THAT YOU", and "SUPPORT IS". Frame 013 returns to the full-bleed studio shot with the caption "AGENT AT". Frame 014 is a card with no speaker and no banner, reading "WOULD YOU POINT AN AGENT AT SOMEONE ELSE'S APP?".
The repository, the license, and the owner all check out against the GitHub API
The transcript opens with "An open source agent that can reverse engineer any app, I checked the REA repo. It's real, MIT licensed." The repository exists at github.com/morluto/rea and the GitHub API confirms the license field as MIT, the primary language as TypeScript, and the repository creation date as 2026-04-14T00:51:32Z. At the time I pulled it on 2026-10-07 the repository showed 10,356 stars, 1,149 forks, 32 watchers, and 81 open issues, with the most recent push at 2026-10-07T05:46:23Z. The owner morluto is an individual GitHub user account opened on 2020-12-22, not an organization, with 162 public repositories and a bio that reads "MTS @ _____". The published npm package is rea-agents, latest version 4.1.0, which recorded 1,291 downloads for the week of 2026-09-28 through 2026-10-04 according to the npm downloads API. The README headline shown in frames 002 through 004 is reproduced correctly: the live README H1 is "REA: Reverse Engineer Anything".
REA is tooling that an agent calls, and the README's own subtitle says so
The transcript calls REA "an open source agent." The README's subtitle under the H1 reads "One MCP for reverse engineering across binaries, applications, and runtime behavior," and the body says "REA connects your agent to tools for inspecting native binaries, JavaScript and Electron apps, .NET assemblies, and websites. You can also use the same tools from your terminal." The reverse engineering is performed by whichever client you already run. REA supplies the MCP server, the CLI, and the workflow instructions that the client invokes. The tool catalog table in the README lists 12 families whose counts sum to 129 tools: 41 native inspection, 21 workspace and observation, 14 investigation workflows, 11 application workflows, 9 browser observation, 7 native macOS utilities, 7 managed PE/CLI, 5 artifact graph, 5 Android APK, 5 Electron analysis, 2 firmware, and 2 JavaScript runtime. Calling that catalog an agent compresses the architecture in a way that matters for anyone deciding whether to install it, because installation registers an MCP server with an existing client rather than adding a new autonomous process.
Deep binary analysis accepts three engines, and the third shipped the same evening as the video
The transcript says "Deep binary analysis needs Hopper, a separately licensed app, or Ghidra that you install yourself." The live README states it with a third option: "Deep native binary analysis requires [Hopper], [Ghidra], or [IDA Pro]. Hopper is separate software with its own license; its demo supports analysis with vendor-defined limits. Ghidra and IDA are bring-your-own providers." The IDA Pro adapter is not an old feature the video overlooked. The CHANGELOG lists feat(ida): add read-only GUI and headless MCP providers (#754) under release 4.1.0, and the commits API puts that merge at 2026-10-06T17:47:05Z with the chore(main): release rea-agents 4.1.0 commit following at 2026-10-06T17:57:26Z. The video posted at 19:23:48 UTC, which is 1 hour 37 minutes after the IDA provider merged and 1 hour 26 minutes after 4.1.0 published. The README describes the adapter as reusing an existing mrexodia/ida-pro-mcp registration in attached mode or running its own headless database supervisor, with initial real workflows covering a Windows GUI and Windows x64 headless IDA 9.3.
Ghidra is free and Apache 2.0 from the NSA, while Hopper's free tier caps sessions at 30 minutes
The video groups Hopper and Ghidra as two flavors of inconvenience without saying what either one costs. Ghidra is developed by the National Security Agency's Research Directorate and released under Apache 2.0, free to download. The latest release is Ghidra 12.1.4, published 2026-09-21T17:38:59Z. REA's README states that it "accepts Ghidra 12.1.x and the 64-bit full JDK that installation declares," that current 12.1 releases require JDK 21 or newer, and that the bridge is verified with Ghidra 12.1.4 and JDK 21. Hopper carries the cost. The Hopper download page offers macOS and Linux builds for Ubuntu 24.04+, Fedora 41+, and 64-bit Arch, and lists three demo restrictions: no save or export of disassembly or modified binaries, a disabled debugger backend, and sessions "limited to 30 minutes." REA's installation guide says setup can install Hopper with explicit consent and run the demo build on a private Xvfb display on Linux, and the README FAQ answers the ownership question plainly: "Setup can install Hopper for you, but Hopper remains separate software with its own license."
The "experimental Windows support" label covers one narrow path, and the on-screen card behind that claim is about 16-bit DOS executables
The transcript closes its caveats with "And Windows support is still experimental." The README scopes that label to a single provider path: "Repository main and npm 4.1.0 include experimental Windows x64 Ghidra support for native x86-64 PE applications on local NTFS, with bundled Job Object, private-DACL, and path-admission controls." The Windows Ghidra P0 guide opens with "Status: experimental Windows x64 support for the read-only P0 boundary," and the README adds that this boundary covers "native, non-managed, non-DLL x86-64 PE applications on fixed local NTFS with 25 read-only operations" and has "no mutation authority." Other Windows behavior is specified differently. Static JavaScript and Electron analysis runs on Windows and the quick start gives a Windows path example, "D:/apps/example". Process capture is unavailable on Windows rather than experimental. Historical-source import returns unsupported_host on native Windows and has to run under WSL or another host. Meanwhile the card held on screen across frames 009 through 012, verbatim "DOS MZ analysis with Ghidra", corresponds to a documentation page whose actual title is "DOS MZ and COM analysis with Ghidra," covering 16-bit real-mode executables. That page is unrelated to Hopper licensing, to bring-your-own Ghidra installation, and to Windows PE support, which are the three claims the voiceover makes while it sits there.
The video's source-code limit is accurate, and the README states it more strictly
Frames 007 and 008 caption "ORIGINAL SOURCE" and "DECOMPILED CODE" under the transcript line "It can't recover the original source code, just readable decompiled code and clues." The README supports this in three places. The capabilities section says "REA shows how it reached its conclusions. It does not claim to recover original source code or automatically clone an application." The Ghidra provider section says "Decompilation produces pseudocode rather than the original source." The FAQ entry titled "Can REA recover the original source code?" answers "No decompiler can guarantee the original source. REA gives an agent pseudocode, assembly, symbols, strings, metadata, and relationships that it can use to explain or compatibly recreate observed behavior." The word "readable" in the transcript is the one soft spot, because pseudocode readability depends entirely on the binary, its optimization level, and whether symbols survived stripping.
Key Takeaways
- Verified:
morluto/reaexists, carries an MIT license, is written in TypeScript, and showed 10,356 stars and 1,149 forks on 2026-10-07 per the GitHub API. The repository was created 2026-04-14. - Verified: REA cannot recover original source code. The README says so in three separate places, including the FAQ line "No decompiler can guarantee the original source."
- Correction: Deep native binary analysis accepts three engines, not two. The README lists Hopper, Ghidra, and IDA Pro. The IDA provider merged at 2026-10-06T17:47:05Z and shipped in
rea-agents4.1.0, which published 1 hour 26 minutes before this video posted. - Correction: REA is an MCP server and CLI that supplies 129 tools across 12 families to an existing agent client. The README subtitle reads "One MCP for reverse engineering across binaries, applications, and runtime behavior."
- Partial correction: "Windows support is still experimental" applies to the Ghidra x64 PE path only, which is read-only with 25 operations on local NTFS. Static JavaScript and Electron analysis already runs on Windows, process capture is unavailable there rather than experimental, and historical-source import returns
unsupported_host. - Partial correction: The on-screen client list in frame 006 names 11 clients and omits Command Code. Command Code MCP registration merged at 2026-10-06T06:15:59Z, roughly 13 hours before the video posted, so the screenshot was already stale at upload. The live README lists 12.
- Context: Ghidra is free and Apache 2.0 licensed, maintained by the NSA Research Directorate, latest release 12.1.4 on 2026-09-21. Hopper's free demo blocks save and export, disables the debugger, and limits sessions to 30 minutes.
- Context: The B-roll card behind the Hopper, Ghidra, and Windows claims reads "DOS MZ analysis with Ghidra," which is a 16-bit real-mode documentation page unrelated to all three claims.
- Unverified: The closing question, "Would you point an agent at someone else's app?", goes unanswered on the legal side. The README's security and privacy sections cover local execution and credential handling. I found no clause in the README assigning responsibility for analyzing software you do not own or license.
Resources
- github.com/morluto/rea establishes the repository exists, is MIT licensed, and carries the description "Reverse engineer anything with agents, from app behavior down to native binaries."
- The live README is the source for the H1 "REA: Reverse Engineer Anything", the three-engine requirement line naming Hopper, Ghidra, and IDA Pro, the 12-client support list, the 12-family tool catalog, and the source-recovery FAQ.
- The CHANGELOG dates release 4.1.0 to 2026-10-06 and lists both
feat(ida): add read-only GUI and headless MCP providers (#754)andfeat(setup): support Command Code MCP registration (#645)in that release. - docs/windows-ghidra-p0.md carries the line "Status: experimental Windows x64 support for the read-only P0 boundary."
- docs/ghidra-dos.md is titled "DOS MZ and COM analysis with Ghidra" and shows that the on-screen card in frames 009 through 012 is a truncated render of that heading.
- docs/installation.md states that Hopper "is separate commercial software with its own license" and that approved setup can install it on macOS and supported Linux distributions.
- github.com/NationalSecurityAgency/ghidra establishes that Ghidra is an NSA Research Directorate project released free under Apache 2.0.
- The GitHub releases API for Ghidra returns tag
Ghidra_12.1.4_build, name "Ghidra 12.1.4", published 2026-09-21T17:38:59Z. - hopperapp.com/download.html lists the macOS and Linux builds and the three demo restrictions, including the 30-minute session limit.
- registry.npmjs.org/rea-agents returns
"latest":"4.1.0"as the published version. - The npm downloads API for rea-agents returns 1,291 downloads for 2026-09-28 through 2026-10-04.
- The GitHub repository API for morluto/rea supplies the star, fork, watcher, issue, creation-date, and push-date figures quoted above.
Published October 6, 2026. Writeup generated from a favorited TikTok.