bitspire/.claude/skills/nostr-check.md
Padreug 723553522c docs: purge stale lamassu naming; fix the hal-check skill's provenance boundary
- @lamassu/clink import examples → @bitSpire/clink, the package's real name.
- machine-installation.md: the service user is `bitspire`, not `lamassu`
  (renamed in configuration.nix long ago; the doc never followed).
- README: clone aiolabs/bitspire, not lamassu-next; the fleet sentence
  claiming batm3/douro run `main` against Lightning.Pub was stale.
- nostr-check skill: table headers say bitSpire.
- hal-check skill: the boundary is c0b69d1, not v8.1.5 (CLAUDE.md corrected
  this 2026-07-04; the skill kept asserting the wrong tag), and the
  "forbidden operations" now reflect the recorded permission —
  reference over port, name the source commit — plus a rule born of the
  GTQ window: no value table without a test over it.

Deliberately kept: every `aiolabs/lamassu-next#NN` issue citation, the
provenance sections, "Ported from lamassu-machine" driver headers, and
the hardware names "Lamassu Sintra/Tejo/Douro" — those are the machines.
2026-10-09 21:58:55 +02:00

125 lines
3.4 KiB
Markdown

# /nostr-check - Nostr Conformity Agent
## Purpose
Validate Nostr Implementation Proposals (NIP) conformity and optimize Nostr-related code.
## Invocation
```
/nostr-check [target] [--nips NIP1,NIP2,...]
```
Where `target` can be:
- A file path
- A directory
- `--events` to validate event structures
- `--relay` to check relay configuration
## Relevant NIPs for bitSpire
### Core NIPs (Must Implement)
| NIP | Description | Usage in bitSpire |
|-----|-------------|------------------|
| NIP-01 | Basic protocol | Event structure, relay communication |
| NIP-19 | bech32 entities | npub, nsec, nprofile encoding |
| NIP-42 | Auth | Private relay authentication |
| NIP-44 | Encrypted payloads | Secure DMs, receipts |
| NIP-59 | Gift wrapping | Anonymous message delivery |
### Application NIPs
| NIP | Description | Usage in bitSpire |
|-----|-------------|------------------|
| NIP-17 | Private DMs | Receipt delivery |
| NIP-47 | Nostr Wallet Connect | Potential wallet integration |
| NIP-57 | Lightning Zaps | Optional tipping |
### Custom Event Kinds
| Kind | Description | Structure |
|------|-------------|-----------|
| 21001 | CLINK Offer | `{ pubkey, relays, priceType, amount? }` |
| 21002 | CLINK Debit | Payment request/response |
| 21003 | CLINK Manage | Operator commands |
| 30078 | Machine Status | Replaceable, `d` tag = "status" |
| 30079 | Transaction Record | Replaceable, `d` tag = "tx:{txid}" |
## Validation Checks
### Event Structure (NIP-01)
```typescript
interface Event {
id: string // 32-byte hex
pubkey: string // 32-byte hex
created_at: number // Unix timestamp
kind: number // Event kind
tags: string[][] // Array of tag arrays
content: string // Arbitrary string
sig: string // 64-byte hex signature
}
```
- [ ] `id` is valid SHA256 of serialized event
- [ ] `pubkey` is valid 32-byte hex
- [ ] `created_at` is reasonable (not far future/past)
- [ ] `kind` is valid for application
- [ ] `tags` are properly formatted
- [ ] `sig` is valid Schnorr signature
### bech32 Encoding (NIP-19)
- [ ] npub/nsec properly encoded
- [ ] nprofile includes relay hints
- [ ] nevent includes author pubkey
- [ ] No confusion between hex and bech32
### Encryption (NIP-44)
- [ ] Using NIP-44 (not deprecated NIP-04)
- [ ] Proper key derivation
- [ ] Random nonce for each message
- [ ] MAC verification before decryption
### Auth (NIP-42)
- [ ] Challenge-response implemented
- [ ] Auth events have proper `relay` tag
- [ ] Auth events signed correctly
- [ ] Timeout handling for auth flow
## Optimization Suggestions
### Relay Communication
- Use connection pooling
- Implement proper reconnection with backoff
- Batch event publishing when possible
- Use REQ filters efficiently
### Event Handling
- Verify signatures before processing
- Cache verified events
- Use proper indexing for event lookups
- Implement proper subscription management
## Output Format
```markdown
## Nostr Conformity: [target]
### NIP Compliance
| NIP | Status | Notes |
|-----|--------|-------|
| NIP-01 | ✅ Pass | |
| NIP-19 | ⚠️ Issue | See below |
### Issues Found
- [ ] `file:line` - Description
### Optimization Opportunities
- [ ] Description with rationale
### Custom Event Validation
| Kind | Valid | Notes |
|------|-------|-------|
| 30078 | ✅ | Machine status properly formatted |
```
## Example Usage
```
/nostr-check packages/nostr-client/src/events.ts --nips NIP-01,NIP-19
```