How else would it work? It is listening for events to sign. That's not insecure. It is a necessary layer of obfuscation, IMO.
Wisp is pretty much entirely vibecode. I like utxo and wisp, but I'm not going to trust ANYONE'S vibecoded slop with my nsec. I value that more than my stack.