Use of SSH agent forwarding is dangerous as it allows an attacker to gain access to more key materials to access more servers. Using it casually in an article about SSH security is a bit worrying.
Not with the confirm option of ssh-add. I've had agent forwarding on for every host (trusted and untrusted) for a decade now, without worry, because my ssh agent confirms with me each use of any ssh key.
Interesting. However in practice, I don't ssh-add my keys, they get loaded on first use by the ssh client. Is there a way to make ssh load keys into the agent with that option set?