AltaySec kurucusu · AltayCTF kaptanı. 2024'ten beri tek odak: dil modellerini ve ajanları kırmak — ve savunmak.
I red-team LLMs and AI agents — prompt injection, MCP / tool poisoning, the invisible-Unicode supply chain — then ship the open-source defenses. Turkish-first, because non-English attacks walk right through English-only filters.
🔴 Now building: Guardian — LLM runtime firewall · Karne — continuous red-teaming control plane (closed alpha).
| 🕵️ uncloak | Paste a SKILL.md / MCP config — hidden instructions appear. Zero install. |
| ⚔️ AI Duel | Send your AI agent to duel: it reads /skills.md, registers itself, attacks and defends. No login. |
| 🍯 ai-honeypot | Live console of attacks captured by a decoy AI agent. |
| 🧭 ATLAS Labs | Bilingual MITRE ATLAS matrix + in-browser attack simulations. |
| 🤗 Hugging Face | 24 datasets · 6 Spaces · a multilingual injection detector (F1 ≈ 0.96, n=75 held-out). |
🏟️ 20+ canlı ücretsiz platform — AltayCTF · Pratik · LLM Security Akademi · Labs · Toolkit · Tycoon → tamamı: altaysec.com.tr/ekosistem
Unofficial community editions — shipped the same day as the Aug 4, 2026 release.
| owasp-llm-top10-2026-tr · selfcheck | LLM Top 10 2026 — Türkçe + machine-readable + interactive self-assessment (TR/EN). |
| owasp-agentic-top10-2026-tr · selfcheck | Agentic Top 10 (ASI01–ASI10) — Türkçe + machine-readable, MITRE ATLAS-mapped. |
| Repo | Why it matters |
|---|---|
| skills-in-the-wild | Open audit of 3,168 real agent extensions — dataset + findings + method. |
| guardrail-arena · live board | Two-axis EN+TR guardrail benchmark — miss-rate and over-refusal. |
| turkish-casefold-evasion | İGNORE.lower() ≠ ignore → 94.6% bypass of naive filters + one-line fix. |
| turkish-over-refusal-set | ProtectAI over-refuses 59% of benign Turkish prompts vs 0.8% English. |
| prompt-injection-corpus | Multilingual injection techniques — each paired with its defense. |
| turkish-pii-redactor | Checksum-validated Turkish PII (TCKN/IBAN/VKN) redaction + KVKK browser demo. |
| llm-security-skills | 7 Agent Skills that turn your coding agent into an LLM security reviewer. |
| damn-vulnerable-agent-skill | 8 deliberately-vulnerable scenarios to learn agent attacks hands-on. |
+50 more — detection rules, KVKK & EU AI Act checklists, MCP hardening, red-team playbooks, glossaries →
Topluluk: LLM-Security-Turkiye · awesome-ai-security-tr (300+ kaynak) · turkce-siber-guvenlik-kaynaklari (TÜGA)
- OWASP GenAI Security Project — Turkish prompt-injection & data-exfiltration test cases merged (2026) · Unicode case-folding guidance merged into the OWASP AI Security & Privacy Guide.
- Research — DOI 10.5281/zenodo.20681557 · AltayDuel (CC-BY-4.0) · ORCID 0009-0008-6518-8944.
- CTF — captain of AltayCTF · #41 global at UIUCTF 2026 (2,426 pts).
- Upstream — open PRs bringing Turkish-locale fixes to Presidio, promptfoo and garak.
- Teaching — LLM Security training at Gazi University (with GaziCyber, 2026) · LLM Security Akademi.
- Programs — Türkiye Siber Vatan · BlueDot Impact — Future of AI (2026).
Kırmızı takım gibi saldırır, mavi takım gibi savunur. · Ankara, Türkiye
