NostrSAFE
A Model Context Protocol (MCP) server that provides Nostr capabilities to AI agents
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
⚠️ This project is no longer maintained. It has been superseded by [nostr-agent-interface](https://github.com/AustinKelsay/nostr-agent-interface) — a newer, improved version with additional Blossom file storage support and an expanded tool set.
For the full MCP server with 48 tools, see: https://github.com/AustinKelsay/nostr-agent-interface
What changed?
The nostr-agent-interface (NAI) builds on this project and adds:
- Blossom file storage — 8 new tools for uploading, downloading, listing, deleting, and mirroring blobs
- Expanded tool count — 48 MCP tools covering profile, notes, relays, DMs, zaps, and now blob storage
- Cleaner architecture — improved module organization and signing via
snstr - Built-in budget monitoring — optional Plaid-connected budget tracking for personal finance
Migrating
If you're using nostr-mcp-server, switch to:
npm install -g nostr-agent-interface
Or point to the source:
git clone https://github.com/AustinKelsay/nostr-agent-interface.git cd nostr-agent-interface npm install && npm run build
Old tool count
This repo contains 40 tools (documented in the git history).
The active repo (nostr-agent-interface) has 48 tools.
75ff656a234cOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add nostr-mcp-server -- npx -y [email protected]
{
"mcpServers": {
"nostr-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (40)
28 read · 11 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analyzeNip19 | read | Analyze any NIP-19 entity or hex string to understand its type and contents |
convertNip19 | read | Convert any NIP-19 entity (npub, nsec, note, nprofile, nevent, naddr) to another format |
createKeypair | read | Generate a new Nostr keypair |
createNostrEvent | write | Create an unsigned Nostr event of any kind (requires pubkey or privateKey to derive pubkey) |
createNote | write | Create a new kind 1 note event (unsigned) |
createProfile | write | Create a new Nostr profile (kind 0 event) |
decryptDmNip44 | read | Decrypt a NIP-17 gift wrapped DM (kind 1059) to reveal the inner kind 14 rumor |
decryptNip04 | read | Decrypt ciphertext using NIP-04 (AES-CBC) for direct messages |
decryptNip44 | read | Decrypt ciphertext using NIP-44 (ChaCha20 + HMAC) |
deleteEvent | destructive | Delete one or more events (kind 5 deletion request) |
encryptNip04 | read | Encrypt plaintext using NIP-04 (AES-CBC) for direct messages |
encryptNip44 | read | Encrypt plaintext using NIP-44 (ChaCha20 + HMAC) |
follow | read | Follow a pubkey by updating your contact list (kind 3) |
getAllZaps | read | Get all zaps (sent and received) for a public key |
getContactList | read | Get a user |
getDmConversationNip04 | read | Fetch and optionally decrypt a NIP-04 DM conversation (kind 4) between you and a peer |
getDmInboxNip44 | read | Fetch and decrypt your NIP-44 DM inbox (NIP-17 gift wraps, kind 1059) |
getFollowing | read | Get pubkeys a user is following (alias of getContactList) |
getKind1Notes | read | Get text notes (kind 1) by public key |
getLongFormNotes | read | Get long-form notes (kind 30023) by public key |
getProfile | read | Get a Nostr profile by public key |
getReceivedZaps | read | Get zaps received by a public key |
getRelayList | read | Get a user |
getSentZaps | read | Get zaps sent by a public key |
postAnonymousNote | write | Post an anonymous note to the Nostr network using a temporary keypair |
postNote | write | Post a note using an existing private key (authenticated posting) |
publishNostrEvent | write | Publish a signed Nostr event to relays |
publishNote | write | Publish a signed note to Nostr relays |
queryEvents | read | Query Nostr events using a generic filter (kinds/authors/ids/tags/timestamps) |
reactToEvent | read | React to an event (kind 7) |
replyToEvent | read | Reply to an event with correct NIP-10 thread tags (kind 1) |
repostEvent | read | Repost an event (kind 6) |
sendAnonymousZap | read | Prepare an anonymous zap to a profile or event |
sendDmNip04 | write | Send a NIP-04 encrypted DM (kind 4) |
sendDmNip44 | write | Send a NIP-44 encrypted DM using NIP-17 gift wrap (kind 1059) |
setRelayList | write | Publish your relay list metadata (NIP-65 kind 10002) |
signNostrEvent | read | Sign an unsigned Nostr event with a private key |
signNote | read | Sign a note event with a private key |
unfollow | read | Unfollow a pubkey by updating your contact list (kind 3) |
updateProfile | write | Update an existing Nostr profile (kind 0 event) |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
deleteEvent
['bolt11', 'lnbc1pvjluezpp5qqqsyqcyq5rqwzqfqqqsyqcyq5rqwzqfqqqsyqcyq5rqwzqfqypqdpl2pkx2ctnv5sxxmmwwd5kgetjypeh2ursdae8g6twvus8g6rfwvs8qun0dfjkxaq8rkx3yf5tcsyz3d73gafnh3cax9rn449d9p5uxz9ezhhypd0elx87sj
@modelcontextprotocol/sdk, @noble/curves, @noble/hashes, @scure/base, light-bolt11-decoder, snstr, ws, zod
Gates applied: no_behavioural_pass.
75ff656a234cfull audit observations/trust-audit/mcp-server/austinkelsay__nostr-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 75ff656a234c | SAFE | B | 89 | first audit |
Questions
What is the Nostr MCP server?
A Model Context Protocol (MCP) server that provides Nostr capabilities to AI agents
What tools does Nostr expose?
40 in total: 28 read-only, 11 that write, and 1 that can delete or overwrite (deleteEvent). Every one is listed on this page with its risk.
Is Nostr safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Nostr need?
No credential environment variables were found in its source, so it appears to need none.
How does Nostr run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as nostr-mcp-server at 3.0.0.
How current is this page?
The grade is for one exact copy of the source (75ff656a234c), read on 2026-10-08. The repository is watched and re-audited when it changes.