KeepassXC has exportable passkeys, so you can avoid the stolen case at least.
Also execs can already enforce their apps only - banking apps for approving transactions are already a thing at least in europe, no fido passkey needed.
There is no requirement that credential managers identify themselves. Please stop spreading misinformation.
But didn't the author hint that this could get blocked?
My general read on passkeys and their implementers is that exportability is seen as a risky feature, and there's a push to make it as opaque as possible, likely through attestation or similar mechanisms.
[1]: https://github.com/keepassxreboot/keepassxc/issues/10407