Unless airgapping every event signature is acceptable to you, there's very little you can do to effectively protect your key.
That would be silky. No one will do that for every single interaction. It's simle. Don't enter your nsec into websites. Use a signing extension or bunker. Done.
Trivial mitigation. Keeping a post-it of your password in a drawer rather than posted on the monitor makes little difference to the cleaning maid. And Biden has a LOT of evil maids in his orbit 😉