Start with a question.

Connect REA to your coding agent, or inspect a local app from your terminal.

You'll need Node.js 22 (22.19+), 24 (24.11+) or 26+, and npm.

With your agent

Run setup to connect REA to your coding agent. Client choices include Claude Code, Codex, Cursor, Gemini CLI, Windsurf and other supported MCP clients.

Terminal
npx rea-agents@latest setup

Choose your client and review the setup plan. REA adds its MCP connection and the matching investigation skill, keeping a backup of existing configuration. It asks before applying the changes.

Restart your client when setup finishes. Give your agent a target path and a specific question. For a JavaScript or Electron app, you might start with:

Look at /absolute/path/to/app and find how it exports data. Show the entry points, calls and dependencies involved, with the source locations for your findings.

Replace the path with your local target. Read the findings, then ask a narrower follow-up about a function or connection you want to understand.

From the terminal

You can start with a JavaScript or Electron application folder or ASAR archive. This path uses Node.js and npm and reads the app without running it.

Static application analysis
npx -y rea-agents@latest analyze-javascript-application \
  /absolute/path/to/app --json

Replace the path with your extracted app directory or .asar file. On Windows, a path such as "D:/apps/example" works here.

The result includes the application's identity, recovered module relationships and evidence locations. It also records relationships that remain unresolved. Use those findings to choose where to investigate next.

If you'd like a permanent rea command in your shell:

Install the CLI
npm install --global rea-agents

Continue with the JavaScript application guide

Working with native binaries

REA connects your agent to a local analysis provider. Choose the tool you already use, configure its connection, then ask about your executable or library.

Ghidra

Use an existing Ghidra 12.1.x installation and a 64-bit JDK 21 or newer on Linux x64 or macOS x64/arm64. Set the paths before running setup:

Connect your Ghidra installation
Ghidra connection · macOS / Linux
export GHIDRA_INSTALL_DIR=/absolute/path/to/ghidra_12.1.4_PUBLIC
export JAVA_HOME=/absolute/path/to/jdk-21
npx -y rea-agents@latest doctor --provider ghidra --json
npx rea-agents@latest setup

Replace both paths with your existing installations. Setup checks them and records valid settings for your selected client. On macOS, use a Ghidra package with the native decompiler matching your host architecture.

Hopper

Connect Hopper on macOS or Linux. Run the setup command above; it detects an existing installation or offers an installation plan for your approval.

On macOS, complete Hopper's first-run choice of demo mode or license activation before an unattended analysis.

IDA

The verified IDA setups use Windows, with an existing MCP registration for an attached GUI or a headless database. Linux and macOS headless analysis remains unverified.

Connect an existing IDA MCP registration

Keep the upstream server's working command, args and optional env in a JSON file. An existing mcpServers object with an ida-pro-mcp entry is also accepted. Point REA at that file before setup:

IDA connection · Windows PowerShell
$env:REA_IDA_MCP_CONFIG = "C:/analysis/ida-mcp.json"
$env:REA_ANALYSIS_PROVIDER = "ida"
npx -y rea-agents@latest doctor --provider ida --json
npx rea-agents@latest setup

The attached profile uses upstream legacy 1.4.0 tools with the original binary already open in IDA. The headless profile uses the upstream database-supervisor API and a registration with "mode": "headless"; real verification covers an IDA 9.3 Windows x64 supervisor. Doctor checks the registration without starting IDA.

Give REA the original executable path, with --provider ida in a CLI query. For an agent, include REA_IDA_MCP_CONFIG in the REA registration's environment and select IDA when opening the binary.

For an existing Ghidra setup, inspect a function with:

Function analysis
rea function /absolute/path/to/program main \
  --provider ghidra --json

Replace main with the function name or address you want to inspect. Each CLI invocation imports and analyzes the target in its own session. Your agent's MCP queries reuse the imported binary while that session is open.

Follow a native analysis example to see how the function result leads to a recovered calculation.

Getting help

If your agent doesn't see REA

Restart or reconnect the client after setup. To check its registration, use a client-scoped report; for Codex:

Check one client
npx -y rea-agents@latest doctor --client codex --json

If a provider needs attention

Check the provider you're using. For Ghidra:

Check one provider
npx -y rea-agents@latest doctor --provider ghidra --json

The report gives the failed check and a suggested next step.