Unfortunately, that is exactly what SSH agent forwarding allows: using that access to move onto other computers you control, because agent forwarding allows an attacker to hijack your connection[0]
Ironically, it would be almost certainly safer to use no Yubikey at all (which only protects the keys that are stored on your workstation) rather than using Agent Forwarding. At least without agent forwarding, the attacker would at least have to gain access to your laptop.
SSH agent forwarding is a tool that should only be used in very limited situations.
Use proxyjump instead: https://userify.com/docs/jumpbox [1] (disclaimer, co-founder of Userify, which essentially keeps your authorized_keys in sync across all of your servers[2])
It's not a bad idea to use one private key per device; for example one for your desktop, one for your laptop. Label them with which is which (whether you use Userify to manage your SSH logins or not). Then, if you lose your laptop, you can remove your laptop's key from all servers without needing to also revoke your desktop's key.
There's no need to use a separate private key for each client or each business function. The definition of the public key is such that your clients cannot derive the private key from the public key. (Of course, if you have to share the private key with someone else, like on a work computer that your IT team has access to, then you should still generate a separate key for them.)
Yubikeys are still an excellent choice to protect your keys; just not as described in this article.
EDIT: see also Stavrosk's excellent link: https://news.ycombinator.com/item?id=26078305
[0] https://jekhokie.github.io/linux/ssh/security/hijacking/2019...