Atlas / MCP servers / austinkelsay / Nostr

NostrSAFE

mcp/austinkelsay/nostr-1

A Model Context Protocol (MCP) server that provides Nostr capabilities to AI agents

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
40 28r · 11w · 1d
Transport
stdio
License
MIT
Stars
37
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

⚠️ This project is no longer maintained. It has been superseded by [nostr-agent-interface](https://github.com/AustinKelsay/nostr-agent-interface) — a newer, improved version with additional Blossom file storage support and an expanded tool set.

For the full MCP server with 48 tools, see: https://github.com/AustinKelsay/nostr-agent-interface

What changed?

The nostr-agent-interface (NAI) builds on this project and adds:

  • Blossom file storage — 8 new tools for uploading, downloading, listing, deleting, and mirroring blobs
  • Expanded tool count — 48 MCP tools covering profile, notes, relays, DMs, zaps, and now blob storage
  • Cleaner architecture — improved module organization and signing via snstr
  • Built-in budget monitoring — optional Plaid-connected budget tracking for personal finance

Migrating

If you're using nostr-mcp-server, switch to:

npm install -g nostr-agent-interface

Or point to the source:

git clone https://github.com/AustinKelsay/nostr-agent-interface.git
cd nostr-agent-interface
npm install && npm run build

Old tool count

This repo contains 40 tools (documented in the git history).

The active repo (nostr-agent-interface) has 48 tools.

Read from source at commit 75ff656a234cOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add nostr-mcp-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "nostr-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (40)

28 read · 11 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analyzeNip19readAnalyze any NIP-19 entity or hex string to understand its type and contents
convertNip19readConvert any NIP-19 entity (npub, nsec, note, nprofile, nevent, naddr) to another format
createKeypairreadGenerate a new Nostr keypair
createNostrEventwriteCreate an unsigned Nostr event of any kind (requires pubkey or privateKey to derive pubkey)
createNotewriteCreate a new kind 1 note event (unsigned)
createProfilewriteCreate a new Nostr profile (kind 0 event)
decryptDmNip44readDecrypt a NIP-17 gift wrapped DM (kind 1059) to reveal the inner kind 14 rumor
decryptNip04readDecrypt ciphertext using NIP-04 (AES-CBC) for direct messages
decryptNip44readDecrypt ciphertext using NIP-44 (ChaCha20 + HMAC)
deleteEventdestructiveDelete one or more events (kind 5 deletion request)
encryptNip04readEncrypt plaintext using NIP-04 (AES-CBC) for direct messages
encryptNip44readEncrypt plaintext using NIP-44 (ChaCha20 + HMAC)
followreadFollow a pubkey by updating your contact list (kind 3)
getAllZapsreadGet all zaps (sent and received) for a public key
getContactListreadGet a user
getDmConversationNip04readFetch and optionally decrypt a NIP-04 DM conversation (kind 4) between you and a peer
getDmInboxNip44readFetch and decrypt your NIP-44 DM inbox (NIP-17 gift wraps, kind 1059)
getFollowingreadGet pubkeys a user is following (alias of getContactList)
getKind1NotesreadGet text notes (kind 1) by public key
getLongFormNotesreadGet long-form notes (kind 30023) by public key
getProfilereadGet a Nostr profile by public key
getReceivedZapsreadGet zaps received by a public key
getRelayListreadGet a user
getSentZapsreadGet zaps sent by a public key
postAnonymousNotewritePost an anonymous note to the Nostr network using a temporary keypair
postNotewritePost a note using an existing private key (authenticated posting)
publishNostrEventwritePublish a signed Nostr event to relays
publishNotewritePublish a signed note to Nostr relays
queryEventsreadQuery Nostr events using a generic filter (kinds/authors/ids/tags/timestamps)
reactToEventreadReact to an event (kind 7)
replyToEventreadReply to an event with correct NIP-10 thread tags (kind 1)
repostEventreadRepost an event (kind 6)
sendAnonymousZapreadPrepare an anonymous zap to a profile or event
sendDmNip04writeSend a NIP-04 encrypted DM (kind 4)
sendDmNip44writeSend a NIP-44 encrypted DM using NIP-17 gift wrap (kind 1059)
setRelayListwritePublish your relay list metadata (NIP-65 kind 10002)
signNostrEventreadSign an unsigned Nostr event with a private key
signNotereadSign a note event with a private key
unfollowreadUnfollow a pubkey by updating your contact list (kind 3)
updateProfilewriteUpdate an existing Nostr profile (kind 0 event)
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
deleteEvent
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
__tests__/zap-tools-tests.test.ts:32
['bolt11', 'lnbc1pvjluezpp5qqqsyqcyq5rqwzqfqqqsyqcyq5rqwzqfqqqsyqcyq5rqwzqfqypqdpl2pkx2ctnv5sxxmmwwd5kgetjypeh2ursdae8g6twvus8g6rfwvs8qun0dfjkxaq8rkx3yf5tcsyz3d73gafnh3cax9rn449d9p5uxz9ezhhypd0elx87sj
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @noble/curves, @noble/hashes, @scure/base, light-bolt11-decoder, snstr, ws, zod
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 75ff656a234cfull audit observations/trust-audit/mcp-server/austinkelsay__nostr-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0875ff656a234cSAFEB89first audit
06

Questions

What is the Nostr MCP server?

A Model Context Protocol (MCP) server that provides Nostr capabilities to AI agents

What tools does Nostr expose?

40 in total: 28 read-only, 11 that write, and 1 that can delete or overwrite (deleteEvent). Every one is listed on this page with its risk.

Is Nostr safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Nostr need?

No credential environment variables were found in its source, so it appears to need none.

How does Nostr run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as nostr-mcp-server at 3.0.0.

How current is this page?

The grade is for one exact copy of the source (75ff656a234c), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement