With Nitrokey/nitrokey-storage-firmware#32 fixed (see Nitrokey/nitrokey-storage-firmware/pull/37) I believe libnitrokey should properly check CRC codes of commands/responses.
A brief look at device_proto.h seems to indicate that this is not the case (please correct me if I am looking at the wrong location). Can/should we change that?