Back to skill

Security audit

nostr-profile

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Nostr profile purpose is coherent, but it handles signing credentials and public profile mutation with under-scoped dependency and raw-key example risks that merit Review before installation.

Review this carefully before installing. Use an isolated environment, prefer the encrypted .nostrkey flow, do not place a raw nsec in environment variables, pin/audit the Python packages if possible, and avoid DiceBear or other third-party image URLs seeded with your npub unless you accept the privacy tradeoff.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
metadata.json:24
Finding

Unpinned Third-Party Packages Expose the Signing Environment to Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:8-14; metadata.json:24-31
Vulnerability Type: Unpinned and externally retrieved dependencies
Risk Level: Medium

Vulnerable Code

SKILL.md:8-14:

yaml
requires:
  bins:
    - pip
install:
  - kind: pip
    package: nostr-profile
    bins: []
  - kind: uv
    package: nostr-profile
    bins: []

metadata.json:24-31:

json
"install": {
  "pip": "nostr-profile"
},
"requires": {
  "python": ">=3.10"
},
"dependencies": [
  "nostrkey>=0.1.1"
],

Technical Analysis

The Skill instructs the platform to install nostr-profile from the public Python package ecosystem without an exact version or integrity hash. Its security-sensitive dependency, nostrkey, also uses an open-ended lower-bound constraint rather than an exact reviewed version.

The installed implementation is not included in the audited artifact. Consequently, the behavior reviewed in the documentation and example cannot establish what code will actually execute after package resolution. A future compromised, malicious, or otherwise unsafe package release could be selected without any modification to this Skill.

This is especially sensitive because the dependencies operate in an environment containing Nostr signing credentials. Package installation and import-time code execution can occur with the privileges of the agent process.

Attack Path

  1. An attacker compromises the publisher account, release pipeline, or distribution artifact for nostr-profile or nostrkey.
  2. The attacker publishes a modified version satisfying the unrestricted dependency declaration.
  3. A user installs or updates the Skill, and the package manager resolves the attacker-controlled release.
  4. Malicious installation hooks, import-time logic, or runtime code executes inside the agent environment.
  5. The malicious dependency reads available credentials, interc ...[truncated 692 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin nostr-profile and nostrkey to exact, reviewed versions.
  • Require cryptographic package hashes through a locked requirements file or equivalent package-manager lockfile.
  • Audit and vendor the security-critical signing implementation when feasible.
  • Use a trusted private package index or explicitly configured approved source rather than relying implicitly on public index resolution.
  • Disable unnecessary installation hooks and install packages in an isolated, non-privileged environment.
  • Separate package installation from the runtime that has access to signing credentials.
  • Introduce automated dependency integrity, provenance, vulnerability, and release-drift checks.

T09 · Insecure Skill Coding Practices

Error
Location
examples/publish_profile.py:11
Finding

Raw Nostr Private Key Loaded from a Process Environment Variable

Content
View full analysis

Vulnerability Details

File Location: examples/publish_profile.py:11
Vulnerability Type: Plaintext sensitive key handling
Risk Level: High

Vulnerable Code

python
identity = Identity.from_nsec(os.environ["NOSTR_NSEC"])

Technical Analysis

The example requires the complete Nostr private key, or nsec, to be placed in the process environment. Environment variables are not an appropriate long-term storage mechanism for identity signing keys. They may be exposed through process diagnostics, crash reports, CI configuration, debugging output, container inspection interfaces, inherited child-process environments, or shell history used to export the value.

This example also conflicts with the safer encrypted .nostrkey workflow documented elsewhere in SKILL.md, which recommends loading the identity from an encrypted file using a passphrase. Because an Nostr private key directly authorizes signatures, disclosure cannot be mitigated by ordinary account access controls.

Attack Path

  1. An operator exports NOSTR_NSEC or configures it in a CI, container, or agent runtime environment.
  2. A local process, diagnostic utility, crash collector, compromised dependency, administrator interface, or improperly protected CI log obtains the process environment.
  3. The attacker extracts the plaintext private key.
  4. The attacker imports the key into an independent Nostr client or signing implementation.
  5. The attacker publishes cryptographically valid profile updates or other Nostr events under the victim's identity.

Impact Assessment

The exposed key grants the ability to impersonate the affected Nostr identity and generate valid signatures without further authorization. An attacker could replace public profile metadata, publish arbitrary events, damage the identity's reputation, and continue impersonation from another system.

The immediate scope is the Nostr identity represented by the key. If th ...[truncated 276 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the raw NOSTR_NSEC environment-variable example.
  • Load the identity from an encrypted .nostrkey file using the documented Identity.load(...) workflow.
  • Obtain the decryption passphrase from an approved secret manager or interactive protected input rather than storing the private key itself in process environment state.
  • Keep decrypted key material in memory only for the minimum time needed to sign an event.
  • Prevent signing credentials from being inherited by child processes.
  • Run signing operations in a narrowly scoped, isolated process with restricted filesystem and network access.
  • Redact secrets from diagnostics and disable environment capture in logs and crash reports.
  • If this example has already been used in an environment where the variable may have leaked, treat the identity as potentially compromised and migrate to a new key.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill uses environment-derived secrets and network-capable code paths but does not declare any explicit tool scope or permissions boundaries. That creates a governance gap: an agent may access environment variables or perform network actions without clear user-visible authorization, increasing the chance of unintended secret use or outbound actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger guidance uses broad natural-language phrases like setting up a profile or giving yourself a name on Nostr, which can overlap with ordinary conversation. In an agent setting, ambiguous triggers can cause the skill to activate and initiate signing or publishing workflows without sufficiently clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The guidance recommends automatic profile image generation and later references third-party image URLs, but it does not warn that using such URLs discloses the user's npub and client access patterns to external services. This can leak metadata, enable tracking, and expose profile associations beyond the intended Nostr relay publication.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill constructs a DiceBear URL containing me.npub as a query parameter, transmitting a persistent public identifier to a third-party service. Even though the key is public, this external disclosure creates an unnecessary correlation point between the operator/agent identity and a separate service, which may log requests and support tracking.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
me = Identity.load("my-identity.nostrkey", passphrase=os.environ["NOSTRKEY_PASSPHRASE"])

# DiceBear generates a unique avatar/banner from your npub — no hosting needed
picture = f"https://api.dicebear.com/7.x/bottts/svg?seed={me.npub}"
banner = f"https://api.dicebear.com/7.x/shapes/svg?seed={me.npub}"

profile = Profile(

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The banner URL also sends me.npub to DiceBear, creating a second external transmission of the same persistent identifier. Repeated third-party requests increase observability and cross-service correlation risk without being necessary for core profile publication.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
# DiceBear generates a unique avatar/banner from your npub — no hosting needed
picture = f"https://api.dicebear.com/7.x/bottts/svg?seed={me.npub}"
banner = f"https://api.dicebear.com/7.x/shapes/svg?seed={me.npub}"

profile = Profile(
    name="Johnny5",

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The update example again recommends sending the user's npub to DiceBear for avatar generation, normalizing ongoing disclosure of a persistent identifier to an external service. Because this appears in day-to-day usage, it increases the likelihood that agents repeatedly leak identity-linked metadata during routine operations.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

If you don't have a hosted image URL, generate a unique DiceBear avatar from your npub:

python
picture = f"https://api.dicebear.com/7.x/bottts/svg?seed={me.npub}"
asyncio.run(update_profile(me, relay, picture=picture))

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code accesses NOSTR_NSEC, which is a private key/credential, but provides no confirmation prompt, warning message, or explanatory comment about handling sensitive secret material. The module docstring describes publishing a profile but does not disclose that a signing key must be supplied from the environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.