Earlier quoted context omitted.
1Password with WebAuthn 2FA is probably better (harder for generic malware to steal), and leagues more convenient.
Not true. The solution I described would survive a local machine compromise (the GPG key is maintained on the Yubikey), the 1Password based solution won’t. How could generic malware steal secrets that are not even on the device? Furthermore, pass encrypts each password separately (I.e GPG generates a new symmetric key for each password). In case of 1password, if the master password is compromised, it’s game over. Als…
That said, your system is well past the point of "password storage is no longer the most economical surface to attack".