Skip to content
View ReazGan's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report ReazGan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ReazGan/README.md

Baran Ayaztaş

Security researcher and full-stack developer based in Istanbul. Started in security, now split between offensive/defensive tooling and web/mobile product work.

Small, single-purpose security CLIs:

AI & LLM security

  • sift - scans AI agent instruction files (CLAUDE.md, .cursorrules, mcp.json) for hidden or planted instructions. pip install siftscan
  • ajar - finds exposed, unauthenticated local AI servers (Ollama, ComfyUI, vLLM, ...). Single binary, Go.

CI/CD & supply chain

  • cicheck - security linter for GitLab CI, CircleCI, Azure, Bitbucket, Drone, Travis. pip install cicheck
  • depsweep - supply-chain risks in npm/pip dependencies: install hooks, typosquats, insecure sources. pip install depsweep
  • dockaudit - Dockerfile and docker-compose security. Single binary, Go.

Web, recon & hardening

  • spill - API keys and secrets left in a site's client-side code. Single binary, Go.
  • subtakeover - subdomain takeover scanner, CNAME fingerprints confirmed with a live HTTP check
  • wraith - HTTP header/TLS/port misconfiguration scanner
  • urlgrave - historical URL/subdomain harvester (Wayback + crt.sh)
  • subrecon - subdomain enumeration
  • pathbrute - HTTP directory/path brute-forcer with soft-404 filtering
  • jwtlint - offline JWT analyzer: alg:none, RS/HS confusion, kid injection, weak secrets. pip install jwtlint
  • sshield - SSH server/client configuration hardening audit. pip install sshield
  • leakscan - secret/API-key scanner for local files
  • cellar - local encrypted secrets vault

Game servers

  • fxsweep - FiveM server backdoor scanner: Cipher/Blum Panel loaders, encoded payloads, webhooks leaked to players. Single binary, Go.

Stack: Python, Go, TypeScript/React, Next.js.

Contact: LinkedIn

Pinned Loading

  1. fxsweep fxsweep Public

    Scans FiveM servers for backdoors (Cipher Panel, Blum Panel and similar), hidden loaders and secrets leaked to players.

    Go 2

  2. ajar ajar Public

    Find exposed, unauthenticated local AI services (Ollama, ComfyUI, SD WebUI, vLLM, ...). Single binary, Go.

    Go 2

  3. spill spill Public

    Find API keys and secrets left in a site's client-side code. Single binary, Go.

    Go 2

  4. sift sift Public

    Scan AI agent instruction files (CLAUDE.md, .cursorrules, AGENTS.md, mcp.json) for hidden or planted instructions.

    Python 1

  5. cicheck cicheck Public

    Security linter for non-GitHub CI pipelines: GitLab CI, CircleCI, Azure Pipelines, Bitbucket, Drone, Travis.

    Python 2

  6. dockaudit dockaudit Public

    Scan Dockerfiles and docker-compose files for security issues. Single binary, Go.

    Go 2