Skip to content
View fevziegeyurtsevenler's full-sized avatar

Block or report fevziegeyurtsevenler

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Fevzi Ege Yurtsevenler — LLM & AI Security · AI Red Team

typing


> whoami

Türkiye'de yapay zekâ güvenliği alanında açık kaynak üreten ve topluluk kuran araştırmacı. Klasik siber güvenlik mühendisliğinden geldim; 2024'ten beri tek odağım dil modellerini ve ajanları kırmak — ve savunmak. 2025'te AI güvenliğine odaklanan AltaySec'i kurdum.

I red-team language models and AI agents: prompt injection, MCP / tool poisoning, RAG attacks, and the invisible-Unicode supply chain. Then I ship the open-source tools to defend against them — Turkish-first, because non-English attacks walk right through English-only filters.


⚡ Live — try it right now

🕵️ uncloak — in your browser Paste a SKILL.md / MCP config and watch a hidden instruction appear. Zero install.
🍯 ai-honeypot — live attack console A dashboard of attacks sent to a decoy AI agent.
🧪 Açık Kaynak Lab All 23 tools, one page.
🤗 Hugging Face collection 15+ datasets + a multilingual injection detector (F1 ≈ 0.96, n=75 held-out).

🗡️ The arsenal — 23 open-source tools

Tools & data

Repo What it does for you
uncloak Reveal hidden prompt injection in Skills / MCP / rules files. Multilingual, SARIF, zero-dep.
skills-in-the-wild Open audit of 3,168 real agent extensions — dataset + findings + method.
ai-honeypot A decoy that captures & classifies attacks on AI agents (+ live dashboard).
prompt-injection-corpus Multilingual injection techniques — each paired with its defense.
prompt-injection-detection-rules 20 portable detection rules (regex+YAML) for guardrails/WAFs.
agent-security-ci Drop uncloak into CI — scan extensions, upload SARIF.
hf-dataset-scan Scan any dataset for smuggled prompt-injection — HF or JSONL, CI gate.
lethal-trifecta-lint Lint an agent's tool manifest for the lethal trifecta (Simon Willison).
turkish-pii-redactor Checksum-validated Turkish PII (TCKN/IBAN/VKN) redaction + KVKK browser demo.

Benchmarks & Turkish guard evaluations (each finding is a bounded probe, not a census)

Repo Finding
guardrail-arena · live board Two-axis EN+TR guardrail benchmark — miss-rate and over-refusal.
turkish-over-refusal-set ProtectAI over-refuses 59% of benign Turkish prompts vs 0.8% English.
guard-blindspots-tr One popular open guard misses 85% of Turkish injections; others are robust.
turkish-casefold-evasion İGNORE.lower() ≠ ignore94.6% bypass of naive filters + one-line fix.

Skills, labs & playbooks

Repo What it does for you
llm-security-skills 7 Agent Skills that turn your coding agent into an LLM security reviewer.
damn-vulnerable-agent-skill 8 deliberately-vulnerable scenarios to learn agent attacks hands-on.
llm-red-team-playbook Scope → threat model → OWASP LLM Top 10 test matrix → report.

Guides, compliance & curation

Repo What it does for you
mcp-security-checklist · owasp-agentic-skills-top10-tr Harden MCP; OWASP Agentic Skills Top 10 in Turkish.
kvkk-ai-compliance-kit · eu-ai-act-technical-checklist KVKK + EU AI Act, as engineering checklists.
ai-security-glossary · awesome-agent-supply-chain-security · awesome-turkish-ai-security Bilingual glossary + two curated lists.

🎖️ Verifiable credentials

  • OWASP GenAI Security Project — Contributor; Turkish prompt-injection & data-exfiltration test cases merged into the GenAI Data Security Initiative dataset (2026).
  • ZenodoDOI 10.5281/zenodo.20681557 · AltayDuel: a Turkish-first arena & open dataset for multi-turn LLM prompt-injection red-teaming (CC-BY-4.0). ORCID 0009-0008-6518-8944.
  • OpenAI Bug Bounty — accepted researcher.
  • Türkiye Siber Vatan (2 terms) — Ministry-of-Industry-and-Technology-verified national cyber talent program · BlueDot ImpactFuture of AI certificate (2026).
  • Gave a university-level LLM Security course at Gazi University (Computer Engineering — as AltaySec).

Kırmızı takım kurar, mavi takım için savunur. · Ankara, Türkiye

Popular repositories Loading

  1. LLM-Security-Turkiye LLM-Security-Turkiye Public

    Türkçe yapay zeka güvenliği için açık kaynak çatı: rehber serisi, uygulamalı akademi, araştırma & deneyler, 23+ araç ve 20 Hugging Face veri seti + model.

    10

  2. LLM-Security-Nedir LLM-Security-Nedir Public

    Kapsamlı bir Türkçe LLM Güvenliği giriş rehberi — yapay zeka güvenliğinin temelleri ve yeni saldırı yüzeyleri.

    8

  3. OWASP-LLM-TOP-10-TURKCE OWASP-LLM-TOP-10-TURKCE Public

    OWASP LLM Top 10 (2025) Kapsamlı Türkçe Rehber — en kritik 10 LLM güvenlik riski, saldırı senaryoları ve savunma stratejileri. Türkçe LLM Security yazı serisinin 3. bölümü.

    6

  4. perisentez perisentez Public

    Prenatal tarama verileriyle genetik sendrom risklerini tahmin eden Streamlit tabanlı medikal karar destek aracı.

    Python 4 1

  5. turkce_wordlist turkce_wordlist Public

    gobuster ile kullanabileceğiniz türkçe-wordlist (eğitim amaçlıdır)

    3

  6. AltaySec-Akademi AltaySec-Akademi Public

    Ücretsiz, oyunlaştırılmış Türkçe siber güvenlik ve pentest akademisi — CTF, lab, quiz ve sertifika odaklı.

    3