bitspire/.claude/skills/nostr-check.md
Padreug 219e7e1e4d refactor(rename): branding strings + active-use docs → bitSpire
Final rename commit covering user-facing copy and the docs that
describe current state. The mechanics of the rename are done after
this; the LNbits backend swap (phase 3) is the next concern.

Code branding strings (Lightning invoice descriptions):
  apps/machine/src/services/lightning.ts
  apps/machine/src/stores/atm.ts
  docs/clink-protocol.md  (example code blocks)
    "Lamassu ATM Payment"        → "bitSpire Payment"
    "Lamassu ATM - Cash Out"     → "bitSpire - Cash Out"
    `Lamassu ATM - Buy ${n} sats`→ `bitSpire - Buy ${n} sats`

Top-level docs:
  README.md, CLAUDE.md — title + intro + dir-tree references.
  deploy/nixos/README.md — title + worktree-path commands.
  docs/machine-installation.md — opening line carries the historical
    note ("Lamassu Next" → "bitSpire"). The body still uses
    `/opt/lamassu/` paths and the `lamassu-kiosk` systemd unit
    because the dev branch is moving to NixOS disk-image flash
    (phase 4) — this AppImage-sideload doc represents the legacy
    deploy path. Leaving the LP/lamassu refs in there as part of
    its historical context; a separate doc will describe the
    NixOS path.
  .claude/skills/nostr-check.md — header only.

DELIBERATELY left as "Lamassu Next" (pedagogical / historical):
  - docs/adr/001-hal-architecture.md — frozen ADR; renaming
    distorts the historical decision context.
  - docs/architecture-comparison.md — deliberately contrasts
    "lamassu-server" (prior) with "lamassu-next" (us at the time
    of writing).

NOT done in this commit (deferred to LNbits/clean-up phase):
  - docker/docker-compose.dev.yml container names
    (lamassu-relay, lamassu-bitcoind, etc.) — these belong to the
    LP-bearing dev stack that 3c/3d will significantly reshape.

Verified: pnpm typecheck clean (12/12 cached).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-06-01 19:08:03 +02:00

125 lines
3.4 KiB
Markdown

# /nostr-check - Nostr Conformity Agent
## Purpose
Validate Nostr Implementation Proposals (NIP) conformity and optimize Nostr-related code.
## Invocation
```
/nostr-check [target] [--nips NIP1,NIP2,...]
```
Where `target` can be:
- A file path
- A directory
- `--events` to validate event structures
- `--relay` to check relay configuration
## Relevant NIPs for bitSpire
### Core NIPs (Must Implement)
| NIP | Description | Usage in Lamassu |
|-----|-------------|------------------|
| NIP-01 | Basic protocol | Event structure, relay communication |
| NIP-19 | bech32 entities | npub, nsec, nprofile encoding |
| NIP-42 | Auth | Private relay authentication |
| NIP-44 | Encrypted payloads | Secure DMs, receipts |
| NIP-59 | Gift wrapping | Anonymous message delivery |
### Application NIPs
| NIP | Description | Usage in Lamassu |
|-----|-------------|------------------|
| NIP-17 | Private DMs | Receipt delivery |
| NIP-47 | Nostr Wallet Connect | Potential wallet integration |
| NIP-57 | Lightning Zaps | Optional tipping |
### Custom Event Kinds
| Kind | Description | Structure |
|------|-------------|-----------|
| 21001 | CLINK Offer | `{ pubkey, relays, priceType, amount? }` |
| 21002 | CLINK Debit | Payment request/response |
| 21003 | CLINK Manage | Operator commands |
| 30078 | Machine Status | Replaceable, `d` tag = "status" |
| 30079 | Transaction Record | Replaceable, `d` tag = "tx:{txid}" |
## Validation Checks
### Event Structure (NIP-01)
```typescript
interface Event {
id: string // 32-byte hex
pubkey: string // 32-byte hex
created_at: number // Unix timestamp
kind: number // Event kind
tags: string[][] // Array of tag arrays
content: string // Arbitrary string
sig: string // 64-byte hex signature
}
```
- [ ] `id` is valid SHA256 of serialized event
- [ ] `pubkey` is valid 32-byte hex
- [ ] `created_at` is reasonable (not far future/past)
- [ ] `kind` is valid for application
- [ ] `tags` are properly formatted
- [ ] `sig` is valid Schnorr signature
### bech32 Encoding (NIP-19)
- [ ] npub/nsec properly encoded
- [ ] nprofile includes relay hints
- [ ] nevent includes author pubkey
- [ ] No confusion between hex and bech32
### Encryption (NIP-44)
- [ ] Using NIP-44 (not deprecated NIP-04)
- [ ] Proper key derivation
- [ ] Random nonce for each message
- [ ] MAC verification before decryption
### Auth (NIP-42)
- [ ] Challenge-response implemented
- [ ] Auth events have proper `relay` tag
- [ ] Auth events signed correctly
- [ ] Timeout handling for auth flow
## Optimization Suggestions
### Relay Communication
- Use connection pooling
- Implement proper reconnection with backoff
- Batch event publishing when possible
- Use REQ filters efficiently
### Event Handling
- Verify signatures before processing
- Cache verified events
- Use proper indexing for event lookups
- Implement proper subscription management
## Output Format
```markdown
## Nostr Conformity: [target]
### NIP Compliance
| NIP | Status | Notes |
|-----|--------|-------|
| NIP-01 | ✅ Pass | |
| NIP-19 | ⚠️ Issue | See below |
### Issues Found
- [ ] `file:line` - Description
### Optimization Opportunities
- [ ] Description with rationale
### Custom Event Validation
| Kind | Valid | Notes |
|------|-------|-------|
| 30078 | ✅ | Machine status properly formatted |
```
## Example Usage
```
/nostr-check packages/nostr-client/src/events.ts --nips NIP-01,NIP-19
```