That's baby+bathwater.
Just use ssh-add -c to have the ssh-agent confirm every use of a key.
Just use ssh-add -c to have the ssh-agent confirm every use of a key.
My assessment still stands. Use proxyjump (-J) instead of proxy command whenever possible.
Also very good for other options that are useful but problematic when used with untrustworthy target hosts, like ForwardX11, GSSAPIAuthentication, weaker *Algorithms (e.g. for those old Cisco boxes with no updates and similar crap).
Another neat trick is just using a ""Match *.my-trustworthy-company-domain.com" block" with an "IdentityFile ~/.ssh/secret-company-internal-key" directive. That key will then be used for those company-internal things, but not for any others, if you don't add it to the agent.