All the more reason to use remote signing with your Nostr client. Keep your nsec out of your client so that the potential for XSS or CSRF attacks can't leak your nsec. Your client shouldn't need/have access to your nsec. Worst that might happen is they trick your remote signer into signing something you didn't authorize, but at least you can recover from that easier than a compromised nsec.