$ whoami
Iliya Dindar
Building AI agents & intelligent bots — hunting whatever breaks them.
AI Agent & Bot Developer · Full-Stack Engineer · Security Researcher
Based in Istanbul. I architect multi-agent LLM pipelines, ship production TypeScript full-stack apps, and build Telegram bots serving thousands — while hunting vulnerabilities through OWASP methodology.
What I'm working on
Multi-Agent LLM Systems
Architecting production LLM pipelines — generator, checker, second-opinion, and escalation models with AI safety layers screening for prompt injection and answer leakage.
Intelligent Bots
20+ Telegram bots delivered to 12K+ users — from multiplayer strategy games to AI-powered group engagement, built with Python and real-time state.
TypeScript Full-Stack
Shipping production apps with Next.js, TanStack Start, React Native, and Cloudflare Workers — end-to-end type-safe from database to UI.
OWASP & Bug Hunting
Deep-diving the OWASP Top 10 through hands-on labs — SSRF, SSTI, XXE, CORS, CSPT, access control, and injection→RCE — plus CTF play and responsible disclosure of real-world vulnerabilities.
Who I am
Education
Computer Engineering, Nişantaşı University — 3rd Year · 2024–2028
Focus
AI Agents, LLM Pipelines & NLP
Languages
English · Persian · Turkish
Security
Penetration Tester · Bug Bounty · OWASP
Builder
AI agents, 20+ Telegram bots (12K+ users), PyPI packages, full-stack apps
Technologies
Languages
AI Agents & LLM
Backend & Frameworks
Data & Infra
Security
Things I've built
Iranian Legal House
AI-native cross-border legal platform — an AI Counsel assistant, a marketplace of bar-verified lawyers across 60+ countries, and an end-to-end matter workflow. AI service on FastAPI + NVIDIA NIM with pgvector retrieval.
Multi-Agent AI Pipeline
Production, RAG-grounded LLM content pipeline for an EdTech product — generator, independent checker, second-opinion, and escalation models, with an AI safety layer screening for prompt injection, answer leakage, and duplicates.
shellstate.com — CTF Platform
Production Capture-The-Flag platform I built and self-host — challenge hosting and scoring on a Dockerized stack (Next.js web, API, PostgreSQL, Redis) behind a Traefik reverse proxy.
HTTP/2 Race Exploit
A Go tool implementing the HTTP/2 single-packet attack to trigger and exploit server-side race conditions — built for CTF and security research.
IliyaMed
Full-stack social platform with PHP frontend, Flask REST API, Next.js admin panel, WebSocket server terminal, and MySQL backend. Deployed in production.
TNT-AI
Real-time speech transcription & translation powered by Whisper AI with offline neural machine translation.
PyRoxi
High-performance async proxy library for Python with SOCKS5/HTTP support. Zero dependencies. Published on PyPI.
Strategic GameBot
Multiplayer war-simulation Telegram bot with real-time strategy mechanics and persistent game state.
TrumpBot
AI-powered Telegram bot for fun group engagement with NLP-driven interactions.
ZipBike
File compression tool supporting Huffman, LZ77, and RLE algorithms with a custom .zbik format.
Achievements
2nd Place — Nişantaşı University Coding Competition (2025)
Microsoft AI Innovators '26 — Selected for the summer program (Azure AI Foundry Local LLM)
Responsible Disclosure — Reported a critical vulnerability in a university portal; confirmed & fixed
20+ Telegram Bots — Including one with 12K+ active users
GitHub Pro — Starstruck, Pull Shark ×2, Pair Extraordinaire, YOLO, Quickdraw
PyPI Published — Open-source Python packages in production
ML Specialization — DeepLearning.AI & Stanford University (Coursera, 2025)
Cybersecurity — Synergy Science '26 — Synergy Maze AI (2026)
18th IT Summit — Participation certificate, İTÜ (2025)
Writeups from the field
DOOM — Chaining CSPT, Open Redirect & XSS
Three findings that look minor on their own — a client-side path traversal, an open redirect, and an XSS sink — chained into a working exploit. Discovery, payload construction, and impact, step by step.
What I can build for you
AI Agents & LLM Systems
Multi-agent LLM pipelines, RAG chatbots, and AI safety layers — self-hosted on NVIDIA NIM or Azure AI Foundry, integrated end-to-end.
Telegram Bots & Full-Stack
Custom bots for automation, games, and communities (20+ delivered, 12K+ users), plus production apps with Next.js and TypeScript.
Security Audits
Junior penetration testing, OWASP Top 10 assessment, and vulnerability reporting for web applications.