So, is there a big advantage to running ssh-agent vs unencrypted 0400 keys in your ~/.ssh directory?
[1] ssh-agent uses some tricks, like making itself setgid, and/or using prctl(PR_SET_DUMPABLE, 0) on Linux to make its memory undumpable.
Your key belongs on your personal device, and agent forwarding enables you to behave as if your key is everywhere you need it to be.