The package nostr-dev-kit was using a dependency (tseep) which downstream would flag as not CSP-safe. Additionally nostr-tools footprint is much smaller.