Security researcher and full-stack developer based in Istanbul. Started in security, now split between offensive/defensive tooling and web/mobile product work.
Small, single-purpose security CLIs:
AI & LLM security
- sift - scans AI agent instruction files (CLAUDE.md, .cursorrules, mcp.json) for hidden or planted instructions.
pip install siftscan - ajar - finds exposed, unauthenticated local AI servers (Ollama, ComfyUI, vLLM, ...). Single binary, Go.
CI/CD & supply chain
- cicheck - security linter for GitLab CI, CircleCI, Azure, Bitbucket, Drone, Travis.
pip install cicheck - depsweep - supply-chain risks in npm/pip dependencies: install hooks, typosquats, insecure sources.
pip install depsweep - dockaudit - Dockerfile and docker-compose security. Single binary, Go.
Web, recon & hardening
- spill - API keys and secrets left in a site's client-side code. Single binary, Go.
- subtakeover - subdomain takeover scanner, CNAME fingerprints confirmed with a live HTTP check
- wraith - HTTP header/TLS/port misconfiguration scanner
- urlgrave - historical URL/subdomain harvester (Wayback + crt.sh)
- subrecon - subdomain enumeration
- pathbrute - HTTP directory/path brute-forcer with soft-404 filtering
- jwtlint - offline JWT analyzer: alg:none, RS/HS confusion, kid injection, weak secrets.
pip install jwtlint - sshield - SSH server/client configuration hardening audit.
pip install sshield - leakscan - secret/API-key scanner for local files
- cellar - local encrypted secrets vault
Game servers
- fxsweep - FiveM server backdoor scanner: Cipher/Blum Panel loaders, encoded payloads, webhooks leaked to players. Single binary, Go.
Stack: Python, Go, TypeScript/React, Next.js.
Contact: LinkedIn