Which is exactly why I use age, the thing’s so simple there’s no way I can fuck it up, and I can plug in an ssh pubkey straight from github.
And I say that even though I'd rather write my own file encryption tool than spend even a minute learning how to use GPG.
This is the kicker. Modern versions of GPG have sane defaults, but if I were a new developer who knew nothing about encryption, I would be very scared of GPG, it's aged documentation, and multitude of encryption and signing methods.
Following the wrong stackoverflow answer, or an out-of-date blog post could easily get you a GPG configuration that is insecure in the year 2023.
The same cannot be said for age, it has no knobs that you can dial to an insecure setting. If you'll forgive the expression, it is "idiot proof".
Like you said though, GPG works, as long as you have that safe workflow.