How are ssh keys going to be leaked, the agent never needs to read them.
A failed SSH connection to a staging server for example, can trivially make it look into .ssh to try to diagnose it. And many other ways, including prompt injection.
https://www.reddit.com/r/ClaudeAI/comments/1q7dszm/claude_al...
https://github.com/anthropics/claude-code/issues/31566
If you were to get pwned by Claude, I would think the method would be Claude rogue installing a compromised npm package.