If someone is planning a malicious exit, it can be very hard to stop them depending on how "integrated" they are.
If they're sharing them individually with you... Then clearly they're not paying attention
You can't. Not from an admin.
Same as how if you are rooted the only advice is to reinstall. It's simply impossible to reliably undo everything from inside the machine.
If you are a company, reimage the machine, then reinstall everything, and copy the code fresh from known good source control (and hope someone was watching source control that the admin did not check something in).
edit: also, use a bastion host which has the keys on it and don't allow them to be removed / used from laptops directly.
Also, the CA mode of OpenSSH is great. More people should use it. It's like PKI but sane.
This problem is not as simple as you are pretending it is