rea.run

Docs · Install

Install REA

Community paraphrase of upstream install notes. Product behavior is defined by github.com/morluto/rea and the rea-agents package on npm. Versions change — re-check before you automate.

Use on software you are authorized to analyze. Compliance

Requirements

1
Node

22 (22.19+), 24 (24.11+), or 26+ plus npm (per upstream).

2
MCP client

Claude Code, Codex, Cursor, Gemini CLI, Windsurf, Grok Build, or other MCP clients — or CLI alone.

3
Native engines

Deep native analysis needs existing Hopper, Ghidra, or IDA. Static JS/Electron does not.

Connect your coding agent

Ask your agent to run setup with approval, or run it yourself:

npx rea-agents@latest setup

Choose your client, review the plan, and approve changes. Setup registers the MCP server and matching investigation skill, backing up existing config. Restart the client afterward.

Manual MCP registration shape (confirm against upstream if your client needs hand-edited JSON):

{
  "mcpServers": {
    "rea": {
      "command": "npx",
      "args": ["-y", "rea-agents@latest", "mcp"]
    }
  }
}

Pin an exact rea-agents@VERSION when you need reproducible installs.

Optional: global CLI

npm install --global rea-agents

Ghidra (bring your own)

REA does not install Ghidra or Java. Export absolute paths, then doctor + setup:

export GHIDRA_INSTALL_DIR=/absolute/path/to/ghidra_PUBLIC
export JAVA_HOME=/absolute/path/to/jdk-21
npx -y rea-agents@latest doctor --provider ghidra --json
npx rea-agents@latest setup

Supported host / Ghidra / JDK combinations are defined upstream — see docs/installation.md in the GitHub repo.

First question to try

After reconnecting the agent, give an absolute path to a target you may analyze and a specific question (entry points, export paths, a named feature). Prefer Evidence + unknowns over speculative narratives.

GitHub Actions demo (no local install)

Prefer watching a pipeline instead of installing locally? Open ylwl1997/rea-run-lab → Actions → workflow demo-smoke → Run workflow. When it finishes, download the Artifacts (smoke / Evidence-style report) from the run summary.

Open Actions demo

  • Runs only the bundled self-owned Electron-shaped demo under demo/ — no arbitrary binary uploads.
  • Authorized / own targets only; see legal boundary.
  • Deeper Electron Evidence teaching: rea-playbook.

Try in GitHub Codespaces

Prefer a disposable cloud shell? Open the public lab ylwl1997/rea-run-lab in Codespaces (Node 22 Dev Container), then run npx rea-agents@latest setup against the bundled self-owned Electron-shaped demo only.

用 Codespaces 试跑 / Open lab

  • No arbitrary binary uploads — lab ships one teaching target under demo/.
  • Authorized / own targets only; see legal boundary.
  • Same lab repo as the Actions demo — two tracks, one demo/.