You have no idea whether that account has been compromised. You have no idea whether somebody has placed arbitrary scripts within that payload. All signing does is provide proof of authorship, it does not provide proof of author other than it was signed by something with the public/private key pair. It does not validate or verify the content. The threat level in these systems is always what’s in the content.
The early web had the same problems. We’ll go through this exact same cycle with nostr.
Just because you can do something, it’s not always a good idea too do it, until. You’be mitigated the risk of bad actors. There will always be bad actors, it’s a fact of life.
Personally, I wouldn’t trust this implementation until it can be verified. Right now, I would treat it as a moderate cool, but cautious of its safety