ssh-agent has prompting and you can set up a Yubikey with ssh.
The problem here was agent forwarding, which you should almost always replace with opening a new connection via ssh -J (or equivalent.)
The problem here was agent forwarding, which you should almost always replace with opening a new connection via ssh -J (or equivalent.)
At least you only would leak a single access, and you would have a higher chance of noticing, but I can also see that if the hijack was done intermittently you might write it off as a glitch...