If you really want to be paranoid you can buy esp32 controllers that sign over usb to a desktop or laptop. I think lnbits sells them.
Otherwise the next most paranoid thing is running grapheneOS on a pixel with a seperate profile that is completely isolated which runs your nostr client and Amber signing app only. Then remove network permissions from Amber so there is zero chance to ever connect to the internet. After that generatr your new nsec or just use the one you are currently using.
Hope that helped.
If you dont want to do any of that just use Amber to sign events so the nsec is not consistently being shared with multiple apps.