Is there a reason there isn't a default signing key generated for each cloned/created repo, or an easy option to toggle to do the same?
Knowing a commit came from one specific clone of a repo would be useful, even if it ended up with more than one key per user. (you could even sign a set of keys to attest that they are you)