Agent skill

Nostr Replaceable Event Mutation Overwrite

by divinevideo in divinevideo/divine-mobile

Fix silent data loss when mutating Nostr replaceable events (Kind 0 profile, Kind 3 contact/follow list, Kind 10002 relay list, etc.) in client apps.

MPL-2.0Auto-check passedMobile

Install Nostr Replaceable Event Mutation Overwrite

skills CLI
$ npx skills add divinevideo/divine-mobile --skill nostr-replaceable-event-mutation-overwrite -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install divinevideo/divine-mobile nostr-replaceable-event-mutation-overwrite --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nostr-replaceable-event-mutation-overwrite .claude/skills/nostr-replaceable-event-mutation-overwrite && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nostr-replaceable-event-mutation-overwrite
GitHub stars
266
Token cost
~1.9k tokens
SKILL.md length
631 words
Files
1
Skills in repo
103
Repo updated
First seen
Licence
MPL-2.0

At a glance

Fix silent data loss when mutating Nostr replaceable events (Kind 0 profile, Kind 3 contact/follow list, Kind 10002 relay list, etc.) in client apps.

  • Works in 4 steps: Always Fetch Fresh State Inside the… → Newest Wins, Per NIP-01 → Refuse to Publish on Total Failure → …
  • Following someone wipes the users entire follow list
  • SKILL.md covers Problem, Context / Trigger Conditions, Solution and Verification, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nostr Replaceable Event Mutation Overwrite is an agent skill from divinevideo/divine-mobile. Fix silent data loss when mutating Nostr replaceable events (Kind 0 profile, Kind 3 contact/follow list, Kind 10002 relay list, etc.) in client apps. Use when: (1) Following someone wipes the user's entire follow list, (2) Updating profile metadata loses existing fields, (3) Fresh browser session or mobile login causes data loss on first action, (4) Replaceable event mutation uses stale or null cached state. Root cause: Nostr replaceable events are full-replace (no partial update), so publishing based on…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Mobile, covering Cross-platform mobile apps and Root cause analysis. It works with Flutter and React. The licence is MPL-2.0.

When your agent uses it

  • Following someone wipes the users entire follow list
  • Updating profile metadata loses existing fields
  • Fresh browser session
  • Mobile login causes data loss on first action

Example prompts

  • “/nostr-replaceable-event-mutation-overwrite”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Always Fetch Fresh State Inside the Mutation
  2. Newest Wins, Per NIP-01
  3. Refuse to Publish on Total Failure
  4. Apply to Both Directions

What it can do on your machine

Read from SKILL.md and the folder at commit 4c622be. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nostr Replaceable Event Mutation Overwrite loads about 1.9k tokens when it runs. Until then it costs about 187 tokens; SKILL.md has 631 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~187
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from divinevideo/divine-mobile at commit 4c622be, republished under its MPL-2.0 licence (© divinevideo). 631 words, ~1,926 tokens.

Download SKILL.mdSave it as .claude/skills/nostr-replaceable-event-mutation-overwrite/SKILL.md (or your agent's skills folder).
name
nostr-replaceable-event-mutation-overwrite
description
Fix silent data loss when mutating Nostr replaceable events (Kind 0 profile, Kind 3 contact/follow list, Kind 10002 relay list, etc.) in client apps. Use when: (1) Following someone wipes the user's entire follow list, (2) Updating profile metadata loses existing fields, (3) Fresh browser session or mobile login causes data loss on first action, (4) Replaceable event mutation uses stale or null cached state. Root cause: Nostr replaceable events are full-replace (no partial update), so publishing based on stale/unloaded cache overwrites the canonical version. Applies to any Nostr client using React, Flutter, or similar reactive frameworks where query state may not be loaded when a mutation fires.
author
Claude Code
version
1.1.0
date
2026-03-23

Nostr Replaceable Event Mutation Overwrite

Problem

Nostr replaceable events (Kind 0, 3, 10002, etc.) use a full-replace model: publishing a new event completely replaces the previous one. If a client publishes a mutation based on stale, incomplete, or null cached state, it silently overwrites the canonical version on relays, causing data loss. The most common case is follow list (Kind 3) wipes when a user follows someone before the client has loaded their existing contact list.

Context / Trigger Conditions

  • User reports "I followed someone and lost all my other follows"
  • Follow/unfollow action on a fresh browser session or mobile login
  • Profile update loses existing metadata fields
  • Relay list update drops existing relays
  • Any mutation on a replaceable event where the UI passes cached state to the mutation function
  • React Query / TanStack Query data is undefined when mutation fires (query still loading)
  • The mutation function accepts the current event as a parameter from the UI layer

Solution

1. Always Fetch Fresh State Inside the Mutation

Never rely solely on the UI's cached/query state. Fetch the latest version of the replaceable event directly from the relay inside the mutation function, before publishing:

typescript
// BAD: Relies on UI cache which may be null/stale
mutationFn: async ({ targetPubkey, currentContactList }) => {
  const currentTags = currentContactList?.tags || []; // null -> [] -> data loss!
  // ... publish with only the new follow
}

// GOOD: Fetches fresh from relay before mutating
mutationFn: async ({ targetPubkey, currentContactList }) => {
  let bestContactList = currentContactList;

  try {
    const relayEvents = await nostr.query([
      { kinds: [3], authors: [userPubkey], limit: 1 },
    ], { signal: AbortSignal.timeout(5000) });

    const relayContactList = relayEvents
      .sort((a, b) => b.created_at - a.created_at)[0] || null;

    if (relayContactList) {
      // NIP-01 already fixes which copy of a replaceable event wins:
      // the higher created_at, and on an exact tie the lower event id.
      // Never compare tag counts — a shorter list is what a legitimate
      // unfollow produces.
      const passed = currentContactList;
      const isNewer =
        !passed ||
        relayContactList.created_at > passed.created_at ||
        (relayContactList.created_at === passed.created_at &&
          relayContactList.id < passed.id);
      if (isNewer) {
        bestContactList = relayContactList;
      }
    }
  } catch {
    // The read failed. It cannot be told apart from "the relay holds
    // nothing", so refuse to publish rather than replacing from a guess.
    throw new Error('Could not confirm the current list. Please try again.');
  }

  if (!bestContactList) {
    throw new Error('Could not load existing data. Please try again.');
  }

  // Now mutate bestContactList...
}
2. Newest Wins, Per NIP-01

Order the relay's version against the cached one by created_at, and on an exact tie by the lower event id. That is the rule relays themselves apply, so it is the only choice that converges.

Do not compare tag counts. "Use whichever has MORE data" looks safe and is not: the newer, authoritative list is shorter whenever the user removed someone, so preferring the longer copy silently resurrects every unfollow, unmuted account, or deleted relay — and republishes it. The heuristic cannot tell "this copy is stale" from "the user removed something", because those two produce the identical shape.

A source that carries no timestamp at all — a bare cached array, a derived REST index — has unknowable freshness, not old freshness. It may seed an empty state, but it must lose to any copy that can name a created_at.

Worked example, including the persistence migration that gives the local cache a timestamp to be ordered by: divinevideo/divine-mobile#8266.

3. Refuse to Publish on Total Failure

If neither the relay fetch nor the UI cache provides data, throw an error instead of publishing an empty/minimal replaceable event. A user-friendly error message is always better than silent data loss.

Show full SKILL.md (241 more words)Show less
4. Apply to Both Directions

Apply this pattern to ALL mutation directions (follow AND unfollow, add AND remove relay, update AND clear profile fields). The unfollow path is just as dangerous as follow.

Verification

Cold-start overwrite:

  1. Open the app in a private/incognito browser window
  2. Log in with an account that has multiple follows
  3. Navigate to a profile and tap Follow IMMEDIATELY (before the page fully loads)
  4. Check that the follow count increased by 1 (not reset to 1)

Cross-device removal — the case a tag-count heuristic passes and still corrupts:

  1. On a second client, unfollow two of several accounts
  2. Cold-start the first client and confirm the removals are still gone
  3. Follow one new account there, then read the relay's kind 3 back and confirm the two removed accounts did not reappear in its p tags

Example

typescript
// Real-world fix from divine-web useFollowUser hook
export function useFollowUser() {
  const { nostr } = useNostr();

  return useMutation({
    mutationFn: async ({ targetPubkey, currentContactList }) => {
      // Step 1: Fetch fresh from relay
      let bestContactList = currentContactList;
      try {
        const events = await nostr.query([
          { kinds: [3], authors: [user.pubkey], limit: 1 }
        ], { signal: AbortSignal.timeout(5000) });
        const relayList = events.sort((a, b) => b.created_at - a.created_at)[0];
        if (relayList) {
          const relayFollows = relayList.tags.filter(t => t[0] === 'p').length;
          const cachedFollows = currentContactList?.tags.filter(t => t[0] === 'p').length ?? 0;
          if (relayFollows >= cachedFollows) bestContactList = relayList;
        }
      } catch { /* fall back to cached */ }

      // Step 2: Refuse if no data
      if (!bestContactList) throw new Error('Could not load follow list');

      // Step 3: Mutate safely
      const tags = [...bestContactList.tags, ['p', targetPubkey]];
      return publishEvent({ kind: 3, tags, content: bestContactList.content });
    }
  });
}

Notes

  • This pattern applies to ALL Nostr replaceable event kinds: Kind 0 (profile), Kind 3 (contacts), Kind 10002 (relay list), Kind 10000 (mute list), Kind 30000+ (addressable)
  • The race condition is most common on mobile browsers where network is slower and users tap quickly
  • Safety check dialogs (like "are you sure?") don't help because they check the same stale cache - the fix must be inside the mutation itself
  • The 5-second timeout on the relay fetch is a reasonable balance between safety and UX
  • Consider also disabling the mutation button while the initial query is loading, as a belt-and-suspenders approach

© divinevideo, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/nostr-replaceable-event-mutation-overwrite of divinevideo/divine-mobile.

Open the folder on GitHubat commit 4c622be

Compare with similar skills

Nostr Replaceable Event Mutation Overwrite next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nostr Replaceable Event Mutation Overwrite compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nostr Replaceable Event Mutation Overwrite this skilldivinevideo/divine-mobile266—~1.9kAutomated safety check: PassMPL-2.0
Stream Docsadrianhajdin/react-native-lingua151—~6.6kAutomated safety check: PassNone
Streamadrianhajdin/react-native-lingua151—~1.9kAutomated safety check: PassNone
Cloudbase Sites RuntimeTencentCloudBase/CloudBase-AI-Toolkit1.1k—~5kAutomated safety check: NotesMIT
Sentry SDK Setupgetsentry/sentry-for-ai268—~1.7kAutomated safety check: PassApache-2.0
Cometchat Flutter V6 Eventscometchat/cometchat-skills130—~1.5kAutomated safety check: PassMIT

Similar skills

  • Stream Docs

    adrianhajdin/react-native-lingua

    Search live Stream SDK documentation for Chat, Video, Feeds, and Moderation.

    151 GitHub stars~6.6k tokensUpdated 4 mo ago
    MobileAuto-check passed
  • Stream

    adrianhajdin/react-native-lingua

    Stream router for Chat, Video, Feeds, and Moderation. An agent skill from adrianhajdin/react-native-lingua.

    151 GitHub stars~1.9k tokensUpdated 4 mo ago
    MobileAuto-check passed
  • Cloudbase Sites Runtime

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses when the user wants to develop, run, preview, save, deploy, or roll back a CloudBase Web app in this conversation as a Lovable/Codex-Sites-like vibe- coding session — i.e.

    1.1k GitHub stars~5k tokensUpdated today
    MobileAuto-check: notes
  • Sentry SDK Setup

    getsentry/sentry-for-ai

    Official

    Set up Sentry in any language or framework. An agent skill from getsentry/sentry-for-ai.

    268 GitHub stars~1.7k tokensUpdated today
    MobileAuto-check passed
  • Cometchat Flutter V6 Events

    cometchat/cometchat-skills

    React to CometChat activity in a Flutter app — SDK listeners (messages, calls, users, groups, connection) versus UI Kit events (CometChatMessageEvents, CometChatGroupEvents, CometChatUserEvents…

    130 GitHub stars~1.5k tokensUpdated 2 days ago
    MobileAuto-check passed
  • Expo

    ericrisco/rsc-harness

    A skill your agent uses when shipping a React Native app with Expo — EAS Build/Submit/Update, eas.json profiles and channels, config plugins, prebuild/CNG, runtime-version policy, OTA updates that…

    167 GitHub stars~2.9k tokensUpdated today
    MobileAuto-check: notes

More from divinevideo/divine-mobile

All 103 skills in this repo
  • Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".

    266 GitHub stars~931 tokensUpdated today
    Auto-check passed
  • Art Direct

    divinevideo/divine-mobile

    Art direction for any content — reads text, PDF, Word, HTML, PPT, then proposes 2-3 creative directions with photography style, mood, and visual language.

    266 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Async Await Null Race Condition

    divinevideo/divine-mobile

    Fix "Null check operator used on a null value" errors when an object is set to null during an async await.

    266 GitHub stars~881 tokensUpdated today
    Auto-check passed
  • AWS V4 Signing Custom Headers Gcs

    divinevideo/divine-mobile

    Add custom metadata headers (x-amz-meta-) to AWS v4 signed requests for GCS S3-compatible API.

    266 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Bash Herestring Newline Secrets

    divinevideo/divine-mobile

    Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.

    266 GitHub stars~791 tokensUpdated today
    Auto-check passed
  • Fix silent video/media processing failures caused by URL extraction code that filters on file extensions (.mp4, .webm, .webp).

    266 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Nostr Replaceable Event Mutation Overwrite

What does Nostr Replaceable Event Mutation Overwrite do?

Fix silent data loss when mutating Nostr replaceable events (Kind 0 profile, Kind 3 contact/follow list, Kind 10002 relay list, etc.) in client apps. Nostr Replaceable Event Mutation Overwrite is an agent skill from divinevideo/divine-mobile.) in client apps.

When should I use Nostr Replaceable Event Mutation Overwrite?

Nostr Replaceable Event Mutation Overwrite fits situations like: following someone wipes the users entire follow list; updating profile metadata loses existing fields; fresh browser session; mobile login causes data loss on first action.

How do I install Nostr Replaceable Event Mutation Overwrite in Claude Code?

Run `npx skills add divinevideo/divine-mobile --skill nostr-replaceable-event-mutation-overwrite -a claude-code`. Or copy the skill folder (.agents/skills/nostr-replaceable-event-mutation-overwrite in divinevideo/divine-mobile) into .claude/skills/nostr-replaceable-event-mutation-overwrite in your project. Claude Code loads it when a task matches its description.

How do I install Nostr Replaceable Event Mutation Overwrite in Codex?

Run `npx skills add divinevideo/divine-mobile --skill nostr-replaceable-event-mutation-overwrite -a codex`. Or copy the skill folder (.agents/skills/nostr-replaceable-event-mutation-overwrite in divinevideo/divine-mobile) into .agents/skills/nostr-replaceable-event-mutation-overwrite in your project. Codex loads it when a task matches its description.

Can I use Nostr Replaceable Event Mutation Overwrite in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add divinevideo/divine-mobile --skill nostr-replaceable-event-mutation-overwrite -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nostr-replaceable-event-mutation-overwrite, .gemini/skills/nostr-replaceable-event-mutation-overwrite, .github/skills/nostr-replaceable-event-mutation-overwrite and .opencode/skills/nostr-replaceable-event-mutation-overwrite in your project.

What does Nostr Replaceable Event Mutation Overwrite need to run?

SKILL.md names no scripts, command-line tools or credentials: Nostr Replaceable Event Mutation Overwrite is instructions for the agent only.

Does Nostr Replaceable Event Mutation Overwrite access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nostr Replaceable Event Mutation Overwrite safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nostr Replaceable Event Mutation Overwrite use?

Nostr Replaceable Event Mutation Overwrite is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nostr Replaceable Event Mutation Overwrite use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nostr Replaceable Event Mutation Overwrite?

Skills that share tags, products or a category with Nostr Replaceable Event Mutation Overwrite: Stream Docs (adrianhajdin/react-native-lingua, 151 stars), Stream (adrianhajdin/react-native-lingua, 151 stars), Cloudbase Sites Runtime (TencentCloudBase/CloudBase-AI-Toolkit, 1.1k stars) and Sentry SDK Setup (getsentry/sentry-for-ai, 268 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nostr Replaceable Event Mutation Overwrite?

divinevideo (a GitHub organization) maintains it in divinevideo/divine-mobile, which has 266 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 8, 2026.

Source: divinevideo/divine-mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.