The idea is sound. Anytime you copy and paste your nsec into an app or website you are potentially exposing it. By using a signing extension like alby, or a signing app like Amber, you centralize that concern. You share your nsec with one app and leverage it to login to all apps/sites. Now you only have to trust/verify a single app/extension rather than all of them
