For anyone not aware, you can use macOS's keychain to store ssh key passwords and have them unlock at login. This way you can have the benefits and convenience of password managers in the command line for SSH certificates. https://apple.stackexchange.com/questions/48502/how-can-i-pe...
> You can configure your key so that they require Touch ID (or Watch) authentication before they're accessed.
That, to me, would be a key thing to want to have: something that tells me "hey, Terminal just wanted to access your Github key. Is that okay?"
If I'm git pushing, that's fine. If I just connected to a random server... that's not okay. What is that trying to do? Deny.