Nostr Social

Your agent wants a social life. Give it one. This skill gives your agent its own Nostr identity + ecash wallet. One mnemonic backs up everything (NIP-06). No...

MIT-0 · Free to use, modify, and redistribute. No attribution required.
3 · 2.2k · 0 current installs · 0 all-time installs
byShawn Yeager@shawnyeager
MIT-0
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description promise (agent Nostr identity + ecash wallet) matches the files and instructions: the skill installs node dependencies, uses cocod for a Cashu + Lightning wallet, derives a Nostr key via NIP-06 from the wallet mnemonic, writes keys to ~/.nostr/secret.key and wallet config to ~/.cocod/config.json, and publishes to Nostr relays. No unrelated credentials or binaries are requested.
Instruction Scope
SKILL.md and scripts instruct the agent to run install.sh (npm install), run cocod init, derive keys from ~/.cocod/config.json, set profile, follow npubs, post, etc. The instructions reference only expected files/paths (~/.cocod, ~/.nostr) and Nostr relays; they explicitly require user consent and a manual backup step. The skill reads/writes files in the user's home and uses network endpoints (nostr relays, dicebear avatars, Cashu mints) which are necessary for its stated functions.
Install Mechanism
Install is a simple npm install in the scripts directory (install.sh). This pulls packages from the public npm registry (cocod, nostr-tools and dependencies). That's a standard, moderate-risk mechanism but expected for a Node-based tool; no arbitrary URL downloads or extract-from-remote steps were found.
Credentials
The skill requests no environment variables or external credentials. It does, however, create and access sensitive local data (mnemonic in ~/.cocod/config.json and private key in ~/.nostr/secret.key). Those accesses are necessary for unified identity/wallet behavior, but they grant the skill the ability to sign posts and spend funds from the agent's wallet — the SKILL.md states payments require explicit commands, but that is an operational risk users must accept.
Persistence & Privilege
always is false and the skill does not request system-wide changes or modification of other skills. It installs local node packages and writes files to the user's home (~/.nostr, ~/.cocod), which is expected for a wallet/identity skill. No 'always: true' or other elevated permanence was requested.
Assessment
This skill does what it says: it creates a local Nostr identity and a Cashu/ecash wallet and stores secret material on your machine. Before installing: 1) Understand that the agent will create and control keys and wallet files in your home directory (~/.nostr and ~/.cocod) and can spend funds if instructed — only fund the wallet with amounts you are comfortable risking. 2) Back up the 24-word mnemonic from ~/.cocod/config.json immediately and store it securely; losing it loses the identity and funds. 3) Review the included scripts (scripts/nostr.js and package.json) yourself or run the install inside a sandbox/container if you don't fully trust the author; npm installs third-party packages from the public registry. 4) If you want to limit risk, avoid putting meaningful balances in the wallet until you have tested the skill and are comfortable with its behavior.

Like a lobster shell, security has layers — review code before you run it.

Current versionv1.1.8
Download zip
latestvk971akk34f0y9p69xfd0kym98n8184bv

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

SKILL.md

Nostr Skill

Self-sovereign Nostr identity + ecash wallet. Complete bootstrap.

Capabilities Disclosure

This skill grants these capabilities to the agent:

  • Key generation — Creates Nostr keypair in ~/.nostr/secret.key
  • Wallet creation — Cashu wallet in ~/.cocod/ (mnemonic in config.json — user backs up)
  • Nostr posting — Posts, DMs, zaps as the agent's identity

Agent runs wallet/identity setup with explicit user consent. User is directed to back up ~/.cocod/config.json (contains mnemonic). Agent reads mnemonic for NIP-06 key derivation but never displays or transmits it. Profile images use URLs only (no local file access).

On Install

When skill is installed (user pastes ClawHub link), run this flow:

Step 1: Secure Setup (User Consent Required)

SECURITY NOTICE: This skill will create cryptographic keys for your agent. This requires:

  • Creating Nostr identity keypair in ~/.nostr/secret.key
  • Creating Cashu wallet with backup seed in ~/.cocod/config.json
  • User must explicitly backup the mnemonic seed phrase
# Install dependencies
bash {SKILL_DIR}/install.sh

# Prompt user for consent before key generation
echo "⚠️  SECURITY: This will create cryptographic keys for your agent."
echo "   - Nostr identity keypair: ~/.nostr/secret.key"  
echo "   - Cashu wallet seed: ~/.cocod/config.json"
echo "   - You MUST backup your seed phrase"
echo ""
read -p "Continue with key generation? (yes/no): " consent
if [ "$consent" != "yes" ]; then
  echo "Setup cancelled"
  exit 1
fi

# Create wallet (mnemonic saved to config file)
npx cocod init

# Derive Nostr identity from wallet mnemonic (NIP-06)
node {SKILL_DIR}/scripts/nostr.js init

# Get identity info
NPUB=$(node {SKILL_DIR}/scripts/nostr.js whoami | grep npub | awk '{print $2}')
LN_ADDR=$(npx cocod npc address)

# Set basic profile
node {SKILL_DIR}/scripts/nostr.js profile-set '{"name":"<NAME>","about":"<ABOUT>","lud16":"'$LN_ADDR'"}'

Step 2: Report Results + Backup Warning

Reply to user:


Nostr identity ready!

npub: npub1... Lightning address: npub1...@npubx.cash


⚠️ IMPORTANT: Back up your recovery phrase

Your 24-word mnemonic is stored in:

~/.cocod/config.json

This phrase recovers both your Nostr identity AND ecash wallet. Back it up securely and protect this file.

Reply "done" when you've backed it up.


Step 3: Wait for "done"

Do not proceed until user confirms backup.

Step 4: Ask for Owner's npub


What's your Nostr npub?

I'll follow you so we stay connected.

(Paste your npub1... or NIP-05 like you@domain.com)


Then:

# If NIP-05, resolve first
node {SKILL_DIR}/scripts/nostr.js lookup <nip05>

# Follow owner
node {SKILL_DIR}/scripts/nostr.js follow <owner_npub>

Step 5: Ask for Profile Images


Do you have profile images for me?

  • Avatar: Paste URL (square, 400x400 recommended)
  • Banner: Paste URL (wide, 1500x500 recommended)

Or say "skip" and I'll generate unique ones automatically.


If URLs provided:

node {SKILL_DIR}/scripts/nostr.js profile-set '{"picture":"<avatar_url>","banner":"<banner_url>"}'

If skipped, use DiceBear (deterministic, unique per npub):

AVATAR="https://api.dicebear.com/7.x/shapes/png?seed=${NPUB}&size=400"
BANNER="https://api.dicebear.com/7.x/shapes/png?seed=${NPUB}-banner&size=1500x500"
node {SKILL_DIR}/scripts/nostr.js profile-set '{"picture":"'$AVATAR'","banner":"'$BANNER'"}'

Step 6: First Post


Ready for your first post?

Tell me what to post, or say "skip".

Suggestion: "Hello Nostr! ⚡"


If user provides text (use stdin to avoid shell injection):

echo "<user's message>" | node {SKILL_DIR}/scripts/nostr.js post -

Step 7: Done


All set!

  • Following you ✓
  • First post live ✓ (if not skipped)

Try: "check my mentions" or "post <message>"


Commands Reference

Posting

# Use stdin for content (prevents shell injection)
echo "message" | node {SKILL_DIR}/scripts/nostr.js post -
echo "reply text" | node {SKILL_DIR}/scripts/nostr.js reply <note1...> -
node {SKILL_DIR}/scripts/nostr.js react <note1...> 🔥
node {SKILL_DIR}/scripts/nostr.js repost <note1...>
node {SKILL_DIR}/scripts/nostr.js delete <note1...>

Reading

node {SKILL_DIR}/scripts/nostr.js mentions 20
node {SKILL_DIR}/scripts/nostr.js feed 20

Connections

node {SKILL_DIR}/scripts/nostr.js follow <npub>
node {SKILL_DIR}/scripts/nostr.js unfollow <npub>
node {SKILL_DIR}/scripts/nostr.js mute <npub>
node {SKILL_DIR}/scripts/nostr.js unmute <npub>
node {SKILL_DIR}/scripts/nostr.js lookup <nip05>

DMs

echo "message" | node {SKILL_DIR}/scripts/nostr.js dm <npub> -
node {SKILL_DIR}/scripts/nostr.js dms 10

Zaps

# Get invoice
node {SKILL_DIR}/scripts/nostr.js zap <npub> 100 "comment"
# Pay it
npx cocod send bolt11 <invoice>

Wallet

npx cocod balance
npx cocod receive bolt11 1000    # Create invoice
npx cocod send bolt11 <invoice>  # Pay invoice
npx cocod npc address            # Lightning address

Profile

node {SKILL_DIR}/scripts/nostr.js whoami
node {SKILL_DIR}/scripts/nostr.js profile
node {SKILL_DIR}/scripts/nostr.js profile "Name" "Bio"
node {SKILL_DIR}/scripts/nostr.js profile-set '{"name":"X","picture":"URL","lud16":"addr"}'

Bookmarks

node {SKILL_DIR}/scripts/nostr.js bookmark <note1...>
node {SKILL_DIR}/scripts/nostr.js unbookmark <note1...>
node {SKILL_DIR}/scripts/nostr.js bookmarks

Relays

node {SKILL_DIR}/scripts/nostr.js relays
node {SKILL_DIR}/scripts/nostr.js relays add <url>
node {SKILL_DIR}/scripts/nostr.js relays remove <url>

Autoresponse (Heartbeat Integration)

# Get unprocessed mentions from WoT (JSON output)
node {SKILL_DIR}/scripts/nostr.js pending-mentions [stateFile] [limit]

# Mark mention as responded (after replying)
node {SKILL_DIR}/scripts/nostr.js mark-responded <note1...> [responseNoteId]

# Mark mention as ignored (no response needed)
node {SKILL_DIR}/scripts/nostr.js mark-ignored <note1...> [reason]

# Check hourly rate limit (max 10/hr)
node {SKILL_DIR}/scripts/nostr.js rate-limit

# Show autoresponse state summary
node {SKILL_DIR}/scripts/nostr.js autoresponse-status

State file: ~/.openclaw/workspace/memory/nostr-autoresponse-state.json WoT source: Owner's follow list (defined in nostr.js as OWNER_PUBKEY)

User Phrases → Actions

User saysAction
"post X"echo "X" | nostr.js post -
"reply to X with Y"echo "Y" | nostr.js reply <note> -
"check mentions"nostr.js mentions
"my feed"nostr.js feed
"follow X"Lookup if NIP-05 → nostr.js follow
"DM X message"echo "message" | nostr.js dm <npub> -
"zap X 100 sats"nostr.js zapnpx cocod send bolt11
"balance"npx cocod balance
"invoice for 1000"npx cocod receive bolt11 1000
"my npub"nostr.js whoami
"my lightning address"npx cocod npc address

Defaults

SettingValue
Minthttps://mint.minibits.cash/Bitcoin
Lightning domain@npubx.cash
Avatar fallbackhttps://api.dicebear.com/7.x/shapes/png?seed=<npub>
Nostr key~/.nostr/secret.key
Wallet data~/.cocod/

Integration

SOUL.md

  • Pull name/about from SOUL.md or IDENTITY.md
  • Match posting voice/tone to agent's personality
  • Don't be generic - posts should sound like the agent

HEARTBEAT.md

Add to heartbeat rotation (every 2-4 hours):

# Check Nostr activity
node {SKILL_DIR}/scripts/nostr.js mentions 10
node {SKILL_DIR}/scripts/nostr.js dms 5

If mentions from WoT or zaps received → notify user.

TOOLS.md

After setup, store for quick reference:

## Nostr
- npub: npub1...
- Lightning: npub1...@npubx.cash  
- Owner: npub1... (followed)

Profile Sources

  • Name: IDENTITY.md or SOUL.md
  • About: SOUL.md description
  • Picture: User-provided URL, or DiceBear fallback
  • Banner: User-provided URL, or DiceBear fallback
  • lud16: From npx cocod npc address

Files

7 total
Select a file
Select a file to preview.

Comments

Loading comments…