Skip to content
Back to skills

Archon Nostr

FSecurity

Derive Nostr identity (npub/nsec) from Archon DID. Use when unifying DID and Nostr identities so both use the same secp256k1 key. Requires existing Archon wallet with ARCHON_PASSPHRASE set.

  • 14 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 7, 2026
testingbashawsgit

Works with

  • cli

Security analysis

F5/100
  • criticalPipes output to a shell interpreter
  • mediumUses curl or wget to download content
  • criticalExfiltrates credentials via HTTP — exact pattern from Snyk ToxicSkills study
  • criticalSends environment variables or credentials to an external URL
  • criticalDownloads and executes remote scripts — classic supply chain attack

Pro scans all 2 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill archon-nostr --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Archon Nostr?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Archon Nostr
[![Security: F — Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-archon-nostr/badge)](https://www.skillsdirectory.com/skills/modbender-archon-nostr)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: archon-nostr
description: Derive Nostr identity (npub/nsec) from Archon DID. Use when unifying DID and Nostr identities so both use the same secp256k1 key. Requires existing Archon wallet with ARCHON_PASSPHRASE set.
---

# Archon Nostr Identity

Derive your Nostr keypair from your Archon DID's secp256k1 verification key. Same key, two protocols.

## Prerequisites

- Archon wallet with existing DID
- `ARCHON_PASSPHRASE` environment variable set
- `nak` CLI: `curl -sSL https://raw.githubusercontent.com/fiatjaf/nak/master/install.sh | sh`

## Derive Keys

Run the derivation script:

```bash
./scripts/derive-nostr.sh
```

This outputs your `nsec`, `npub`, and hex pubkey derived from `m/44'/0'/0'/0/0`.

## Save Keys

```bash
mkdir -p ~/.clawstr
# Save the nsec output from above
echo "nsec1..." > ~/.clawstr/secret.key
chmod 600 ~/.clawstr/secret.key
```

## Update DID Document

Add Nostr identity for discoverability:

```bash
npx @didcid/keymaster set-property YourIdName nostr \
  '{"npub":"npub1...","pubkey":"<hex-pubkey>"}'
```

## Create Nostr Profile

```bash
echo '{
  "kind": 0,
  "content": "{\"name\":\"YourName\",\"about\":\"Your bio. DID: did:cid:...\"}"
}' | nak event --sec $(cat ~/.clawstr/secret.key) \
  wss://relay.ditto.pub wss://relay.primal.net wss://relay.damus.io wss://nos.lol
```

## Verify Unification

The DID's JWK `x` coordinate (base64url) decodes to the same hex as your Nostr pubkey:

```bash
npx @didcid/keymaster resolve-id | jq -r '.didDocument.verificationMethod[0].publicKeyJwk.x'
# Decode base64url → hex should match your pubkey
```

## Why This Works

Archon uses `m/44'/0'/0'/0/0` (Bitcoin BIP44 path) for DID keys. Nostr uses raw secp256k1. Same curve, same key — just different encodings.

Files in this skill

  • SKILL.md1.8 KB
  • scripts/derive-nostr.sh1.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…