For nostr:npub1j9kttlc86w63emmldd4h74rekyqpksqup6p9trhp5gjsf...

Leo Wandersleb

npub1gm7tuvr9atc6u7q3gevjfeyfyvmrlul4y67k7u7hcxztz67ceexs078rf6

hex

d4d75a2a456b5546b9de366e2db8a45506b0255c9b8a2583e54db15c09087b0e

nevent

nevent1qqsdf4669fzkk42xh80rvm3dhzj92p4sy4wfhz39s0j5mv2upyy8krsprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsydl97xpj74udw0qg5vkfyujyjxd3l706jd0t0w0turp93d0vvungqzv8v6

Kind-1 (TextNote)

2026-08-10T10:17:52Z

↳ Reply to Event not found

4131d9133e47800bc8613e60cc2b943ec187ac148ecd717d951814a81ad10c7e...

For nostr:npub1j9kttlc86w63emmldd4h74rekyqpksqup6p9trhp5gjsf374qlyszvuswx I'm thinking about this a lot, together with Project Loupe, too. The problem I see is "responsible disclosure". You will always find something and even the stuff you might want to responsibly disclose at first sight might not be an issue after all, so what will you signal and when and to whom?

I'd happily show what people signal on WalletScrutiny. Make clear attestations.

Known pubkey attests that commit X of project Y was checked with prompt Z on model A with these results ... Highest criticality found: B

Let's agree on a nostr event format. We might not engage in producing those events as "WalletScrutiny" but with clear attribution to nostr accounts I see no problem showing them.

Raw JSON

{
  "kind": 1,
  "id": "d4d75a2a456b5546b9de366e2db8a45506b0255c9b8a2583e54db15c09087b0e",
  "pubkey": "46fcbe3065eaf1ae7811465924e48923363ff3f526bd6f73d7c184b16bd8ce4d",
  "created_at": 1786357072,
  "tags": [
    [
      "e",
      "4131d9133e47800bc8613e60cc2b943ec187ac148ecd717d951814a81ad10c7e",
      "wss://nos.lol/",
      "root",
      "dab6c6065c439b9bafb0b0f1ff5a0c68273bce5c1959a4158ad6a70851f507b6"
    ],
    [
      "p",
      "916cb5ff07d3b51cef7f6b6b7f5479b1001b401c0e82558ee1a22504c7d507c9"
    ],
    [
      "p",
      "dab6c6065c439b9bafb0b0f1ff5a0c68273bce5c1959a4158ad6a70851f507b6"
    ]
  ],
  "content": "For nostr:npub1j9kttlc86w63emmldd4h74rekyqpksqup6p9trhp5gjsf374qlyszvuswx I'm thinking about this a lot, together with Project Loupe, too. The problem I see is \"responsible disclosure\". You will always find something and even the stuff you might want to responsibly disclose at first sight might not be an issue after all, so what will you signal and when and to whom?\n\nI'd happily show what people signal on WalletScrutiny. Make clear attestations.\n\nKnown pubkey attests that commit X of project Y was checked with prompt Z on model A with these results ... Highest criticality found: B\n\nLet's agree on a nostr event format. We might not engage in producing those events as \"WalletScrutiny\" but with clear attribution to nostr accounts I see no problem showing them.",
  "sig": "10880427a4ec7fd8c766766d173578ba69273f28ef1f474dc5ab75255025e8a8f6654bffa242a2609b15c9a9f181d1bd65762251849ac7aefbd7977ec996d978"
}