The longer the better. A memorable sentence is a good place to start.
ssh-agent will cache the passphrase in memory, which helps avoid needing to type in a long phrase repeatedly.
But it's worth saying that if any private key is leaked (passphrase or not), it's time to revoke it and generate a new one.
Having a passphrase in place raises the bar from "key leaked, 3rd party has access to everything" to "key leaked, 3rd party has to now attempt to crack the passphrase". It mitigates a very bad scenario and buys time.