> potentially increasing the risk for the other secrets stored in the same password manager.
As pointed to me by a friend, this is one reason not to give in to the convenience of the secrets manager you already use.
My use case for fnox with keepassdb back-end was partially validated but as I mentioned elsewhere in the thread, having to set master password in an env var is a bit of snag for the workflow.