> This doesn’t actually pose much additional security risk because by hypothesis anyone who can read this file has read access to your current private ssh keys already.
Yes, but they don't have access to my password. That's kind of the point. Having a password-protected private key file is much less useful without the password. If you're going to store the password, might as well just remove it and save yourself the trouble.