Collection criteria: GitHub Trending bot issue happydog-intj/ai-xiaohongshu-daily #545 (dated 2026-10-09, created 2026-10-08 UTC) was used for today’s numbers and #542 (2026-10-08) for the previous day. The primary metric is stars today. Repos above 40k total stars (cathrynlavery/diagram-design 46.0k, mattpocock/skills 280.8k, thedotmack/claude-mem 98.3k) were excluded, and anthropics/knowledge-work-plugins (+309, 27.4k total) was left out because its daily growth relative to total stars was only about 1%. Rain1er/trending #399 (October 8) surfaced in search but could not be fetched, so it was not used for cross-checking.
morluto/rea — +7,744 ⭐ today
https://github.com/morluto/rea
Total stars: 22,448 · Day-over-day: +4,666 → +7,744 (+66%, 3 days in a row) · Language: TypeScript · License: MIT
REA (Reverse Engineer Anything) is an open-source reverse-engineering toolkit that lets AI agents investigate software from an app’s observable behavior down to its native binaries, explaining how a feature works with evidence even when no source code is available. A CLI and an MCP server share the same workflows and evidence formats; an investigation workspace, a target-bound session router and a deterministic deep-provider registry select analysis engines such as Hopper (the default) or a read-only Ghidra provider (Linux, with experimental Windows x64), and provider failures never silently fall back to another engine. Every result is recorded in an Evidence v2 format with provider identity, confidence, limitations and locations. The project explicitly does not claim to recover original source code or clone apps; dynamic features are off by default and require operator policy plus per-call approval, and all analysis runs locally. A guided setup that registers the MCP server with Claude Code, Codex, Cursor, Gemini CLI and others lets coding-agent users plug it in immediately, which appears to be driving its third straight day of accelerating growth.
Key features:
- Native binary analysis: procedure listings, pseudocode, assembly, strings, cross-references, call graphs, control-flow graphs and function dossiers
- Feature tracing from strings or symbols to code, batch decompilation, Swift and Objective-C metadata handling
- Artifact handling: inventory and extraction of ZIP, APK, IPA, MSIX, AppX and ASAR, plus .NET PE/CLI triage without executing the target
- JavaScript/Electron static mapping and source-map handling, passive browser CDP observation and attach-only Node/Electron inspector sessions
- Controlled capture via Process Capture v4 and Playwright, plus two-version artifact and function comparisons
Practical use: Have agents trace authentication, storage, update and networking flows in undocumented legacy or third-party apps with evidence, and compare behavior across versions for security audits and migrations.
#ReverseEngineering #BinaryAnalysis #MCP #Ghidra #AIAgents #SecurityResearch
Leave a comment