Wuxiang: evaluate agent RE recovery (research fixtures)
Most showcase pages teach **doing** RE. Wuxiang asks the opposite lab question: can you **measure** whether an agent recovered protected behavior — with honest limits.
What it is. MIT research toolkit: annotate functions, transform IR via a project-local LLVM SDK, verify/native differential tests, JSON coverage reports. Bootstrap downloads a pinned LLVM SDK with SHA-256 checks.
Relation to REA. REA/Ghidra are optional external analyzers for evaluation sessions — not bundled. Upstream states anti-REA effectiveness is unproven.
Workflow. doctor → protect/verify on example configs → unittest → optional agent analysis on your research builds.
Evaluation. Unique “eval” niche on the wall. Keep it in the lab; do not reframe as a commercial protection product pitch.
Compliance
Research fixtures only. Not malware packaging advice, not a crack shield for commercial apps, not a guarantee against REA.
Takeaways
- Measure recovery; don’t overclaim “anti-REA.”
- Fixtures ≠ shipping DRM.
- Keep untrusted binaries in disposable VMs.
Related on rea.run
More on-site cases