Guide
REA Setup for Hermes Agent and OpenClaw
Install REA from the Tools dashboard, then ask your bot to inspect a local JavaScript or Electron application or a .NET assembly. This guide covers the hosted static-analysis workflow and how to read its evidence.
What the hosted REA install does
REA (Reverse Engineer Anything) is an open-source reverse engineering toolkit. OpenClaw Launch installs rea-agents 6.4.0 on demand, together with the openclaw-launch-rea skill. Hermes Agent and OpenClaw use the same dashboard install steps; the tool and skill paths differ. The hosted wrapper exposes the four commands below and reads the supplied files without executing the target application.
Use this workflow to map a packaged Electron app, understand JavaScript module relationships, or examine metadata and CIL in a managed .NET assembly. Inspect software you own or have permission to analyze. Findings help direct a code investigation; they do not establish that a feature executed or that an application is safe.
Official REA repository and README
| Hosted command | Input | Useful questions |
|---|---|---|
analyze-javascript-application | Local ASAR file or extracted JavaScript/Electron application directory | Which modules and imports are present? What Electron main/preload/renderer, IPC, or native add-on relationships are visible in the files? |
inspect-managed-artifact | Local PE file containing a managed .NET assembly | What assembly identity, metadata, references, and managed structure can be read? |
inspect-managed-members | The same managed assembly | Which types, method signatures, CIL instructions, calls, and field accesses can be inspected? |
inspect-managed-native-boundaries | The same managed assembly | Which native dependencies and entry points does the managed metadata declare, including P/Invoke boundaries? |
The dashboard package does not include REA MCP setup, browser or Electron runtime capture, native binary decompilers such as Ghidra, Hopper, or IDA, or source recovery workflows. Inspecting a managed/native boundary does not decompile the native library. Upstream REA has a broader tool surface; its README is not the list of commands available through this hosted wrapper.
1. Install REA on the bot you will use
- Open Dashboard → Tools and select your running Hermes Agent instance under “Install to instance”. The same steps apply to a running OpenClaw instance.
- Search for REA. Check the selected instance again, then click Install on the REA card.
- Wait for installation to finish. Use Refresh status until the card says Installed. Installing is an in-progress state, not confirmation that the tool is ready.
- Return to chat with that same bot. Ask it to read the openclaw-launch-rea skill before starting an inspection.
Open Dashboard → Tools · REA tool details
Installed tool and skill paths
These are container paths for the dashboard-managed installation. You do not need to install a global CLI, run REA setup, or configure an MCP endpoint to follow this guide. The bot needs shell/exec access to invoke the wrapper.
Hermes Agent
Wrapper: /opt/data/tools/rea-6.4.0/rea
Skill: /opt/data/skills/openclaw-launch-rea/SKILL.md
OpenClaw
Wrapper: /home/node/.openclaw/tools/rea-6.4.0/rea
Skill: /home/node/.openclaw/workspace/skills/openclaw-launch-rea/SKILL.md
2. Put the input in the same hosted instance
REA accepts an absolute local path visible to your hosted bot. A path such as /Users/you/Desktop/app.asar on your laptop is not a path inside that bot. A pasted filename or a link also does not establish that the file is present.
- In the dashboard, open the same instance’s Files panel. If your account has Files access, choose a working folder and use Upload for an ASAR, DLL, or EXE. Use Upload folder for an already-extracted JavaScript application directory.
- The Files uploader has a 50 MB per-file limit. Folder uploads preserve the selected folder hierarchy, but do not unpack an archive. A ZIP file is not an extracted app directory; an ASAR can be supplied directly to the JavaScript command.
- After the upload succeeds, ask your bot to locate that file or directory and confirm its absolute path. If the file is already in the instance, have the bot confirm that existing path instead.
- Keep the application files needed for your question together. If an assembly or application depends on files you did not supply, ask the bot to record the missing evidence rather than fill the gap with an assumption.
I uploaded <FILE_OR_FOLDER_NAME> using this bot’s Files panel. Locate it in your local filesystem and tell me the absolute path. Do not run the application. Confirm whether it is an ASAR, an extracted JavaScript app directory, or a managed .NET assembly before using REA.3. Ask a focused question in chat
Replace every placeholder with your own value. Use the confirmed container path, and start with one feature or one assembly. Ask for file names, method names, or metadata references supporting each conclusion, plus any limitations reported by REA.
Map an Electron app or extracted JavaScript folder
Read the openclaw-launch-rea skill. I am authorized to inspect <ABSOLUTE_PATH_TO_APP_ASAR_OR_EXTRACTED_APP_DIRECTORY>. Use analyze-javascript-application through the managed wrapper. Explain how <FEATURE_NAME> is represented in the available files: identify relevant modules, imports, and any Electron IPC boundaries. Cite the supporting file or module evidence, separate confirmed facts from hypotheses, and list missing evidence. Do not execute the target.Inspect a .NET assembly and its methods
Read the openclaw-launch-rea skill. I am authorized to inspect <ABSOLUTE_PATH_TO_MANAGED_DLL_OR_EXE>. First use inspect-managed-artifact, then inspect-managed-members through the managed wrapper. Summarize the assembly identity, relevant types and methods, and available CIL evidence for <METHOD_OR_FEATURE>. Report unsupported or unreadable parts explicitly. Do not load or execute the assembly, and do not claim the original C# source was recovered.Find declared managed-to-native dependencies
Read the openclaw-launch-rea skill. For <ABSOLUTE_PATH_TO_MANAGED_DLL_OR_EXE>, use inspect-managed-native-boundaries through the managed wrapper. List the declared native modules and entry points, including P/Invoke metadata where available, and explain which methods reference them. Distinguish declarations from runtime library resolution. Do not execute the assembly or decompile any native library.Optional: the exact wrapper invocation
If you are using a terminal inside the selected bot, each invocation takes exactly two arguments: a supported command and an absolute local input path. Quote paths containing spaces. The wrapper does not accept additional flags such as --json, setup, update, or arbitrary upstream commands. The examples below use placeholder paths that you must replace.
Hermes Agent
/opt/data/tools/rea-6.4.0/rea analyze-javascript-application "/ABSOLUTE/PATH/app.asar"
/opt/data/tools/rea-6.4.0/rea inspect-managed-artifact "/ABSOLUTE/PATH/Application.dll"
/opt/data/tools/rea-6.4.0/rea inspect-managed-members "/ABSOLUTE/PATH/Application.dll"
/opt/data/tools/rea-6.4.0/rea inspect-managed-native-boundaries "/ABSOLUTE/PATH/Application.dll"OpenClaw
/home/node/.openclaw/tools/rea-6.4.0/rea analyze-javascript-application "/ABSOLUTE/PATH/app.asar"
/home/node/.openclaw/tools/rea-6.4.0/rea inspect-managed-artifact "/ABSOLUTE/PATH/Application.dll"
/home/node/.openclaw/tools/rea-6.4.0/rea inspect-managed-members "/ABSOLUTE/PATH/Application.dll"
/home/node/.openclaw/tools/rea-6.4.0/rea inspect-managed-native-boundaries "/ABSOLUTE/PATH/Application.dll"4. Turn the output into an evidence-based explanation
- For JavaScript/Electron, ask the bot to connect its explanation to modules, imports, and boundaries found in the supplied package. Bundled, minified, generated, or missing files may limit the result. File relationships alone do not prove that a branch runs.
- For .NET, distinguish assembly metadata and decoded CIL from reconstructed high-level source. A member inspection may be incomplete or unsupported. NativeAOT binaries may lack ordinary CIL method bodies; the hosted wrapper is not a native decompiler.
- For native boundaries, a declared library or entry point is a static fact. It does not prove which library the runtime loaded, whether the call happened, or what the native implementation does.
- Ask for a final report with the input path, commands used, supporting evidence, open questions, and a suggested next investigation. Preserve the original input so you can compare the explanation against the same artifact later.
Official REA managed-code evidence and limitations
Troubleshooting
No running instance or Install is unavailable
Start or deploy a supported Hermes Agent or OpenClaw bot, then return to Tools and select it. A tool installed on a different bot is not available in this one. Check the card’s current availability message before retrying.
Installed, but the bot says it cannot find REA
Confirm that Tools and chat refer to the same instance. Ask the bot to read the skill at its installed path and check the wrapper path shown above. If the existing conversation still uses an old tool context, start a new chat session and ask it to read the skill again. Do not assume the installation restarted the bot or that the bare rea command is on PATH.
The file cannot be found
Verify that the upload completed in this bot’s Files panel, then ask the bot to report the absolute path and confirm it can read it. A laptop path, filename, chat attachment, or URL is not proof of a readable local input. Check the 50 MB per-file limit if an upload was skipped.
Unsupported command or Usage: rea <static-command> <local-path>
Use one of the four commands in the table with one absolute path and no extra flags. MCP registration, setup, update, capture, native decompilation, and source recovery commands are outside this managed installation.
The result does not answer the feature question
Check the input type and the files supplied. Try a narrower question about a module, method, or declared dependency that appears in the result. Treat parsing limitations and missing code as unresolved questions; static inspection cannot provide runtime observations.
Remove REA from this bot
Open Dashboard → Tools, select the instance, find REA, and click Uninstall. Confirm the dashboard prompt, then refresh the status. This removes the dashboard-managed REA tool and its openclaw-launch-rea skill. It is not a cleanup workflow for the input files you uploaded; manage those separately in Files.
Frequently asked questions
Does REA work with Hermes Agent?
Yes. OpenClaw Launch offers the managed REA install for both Hermes Agent and OpenClaw. The dashboard steps and four static commands are the same, while the tool and skill paths differ.
Is this the upstream REA stdio MCP server?
No. Upstream REA provides an MCP server, including a stdio setup workflow. This dashboard installation uses a restricted local CLI wrapper and a skill; it does not register a stdio MCP server or require an MCP URL.
Can I inspect an Electron ASAR without launching the app?
Yes. The hosted analyze-javascript-application command accepts a local ASAR or extracted application directory and performs static inspection without running the target. Uploading a folder does not automatically extract an archive.
Can REA recover C# source or decompile a native binary here?
This installation supports static .NET metadata, members, CIL, and declared native boundaries. It does not include source recovery workflows or native binary decompilers. CIL and metadata are not a guarantee of recovering the original source.
Does an analysis prove the application is safe?
No. Static findings describe evidence in the supplied files, with parsing and coverage limitations. They do not prove runtime behavior or provide a security guarantee.