On the morning of October 7, 2026 (IST), morluto/rea ("Reverse Engineer Anything") drew the most new stars of any repository on GitHub's daily trending page: 2,956 that day. The MIT-licensed repository was created in April and has about 9,700 stars in total, so this is a surge for an existing project, not a launch.
What REA does
REA is "One MCP for reverse engineering across binaries, applications, and runtime behavior." Its README pitch is direct: "See a feature in an app that you want in your own product? Ask your agent to investigate it with REA. It can inspect the app without its source code, explain how the feature works, show the evidence, and build a version for your project."
- Targets: native binaries, JavaScript and Electron apps, .NET assemblies, websites, and (with a separately supplied JADX) static Android APK analysis.
- Engines: deep native analysis uses Hopper, Ghidra or IDA Pro; static JavaScript analysis needs neither. REA can reuse an existing IDA MCP registration.
- Agents: setup registers it with Claude Code, Claude Desktop, Codex, Cursor, Gemini CLI, Windsurf, Devin, OpenCode, GitHub Copilot CLI, VS Code and others, and installs a matching workflow skill.
- Guardrails in the tool: setup shows the exact config changes before applying them and backs up existing configuration; Ghidra analysis runs on "a temporary copy of the target"; results come with "the evidence and limitations behind each conclusion."
Also climbing: skills that shape how agents behave
mattpocock/skills ("Skills for Real Engineers", 889 stars that day) and ayghri/i-have-adhd (326), "A skill to stop your coding agent from burying the answer," continue the run of skill packs on the list. Returning repos include tester-army/e2e and text-to-cad, covered here yesterday, and pbakaus/impeccable.
The adoption constraint is legal and ethical, not technical. Defenders already use these tools on malware and on their own software, and AI labs now gate this work: Anthropic's Cyber Verification Program, expanded on October 6, lists "reverse-engineering malware" as a defensive use for its entry tier. REA's headline use case, though, is different -- copying a feature out of someone else's app. Many software licences forbid reverse engineering, and anti-circumvention law applies in some cases. Analysis: teams adopting REA should limit it to binaries they own, malware samples and interoperability work their lawyers have cleared.
What to watch. Whether REA adds scope controls, such as an allowlist of targets, as usage grows, and whether agent vendors start treating reverse-engineering MCPs the way they treat other high-risk tools.
REA drew the most stars on GitHub's daily trending page on October 7 -- 2,956 in a day -- by connecting coding agents to Ghidra, Hopper and IDA for analysing binaries, Electron apps and websites -- useful for defenders, but its 'copy a feature you like' pitch runs straight into licence terms and anti-circumvention law.