GPG::SSH; notes for current best practices

When I start at a new company, I always do a refresher on my key security. One thing I always hate about SSH is that the encryption scheme is pretty basic actually, and once your ssh-agent is loaded- anything can just request a sign/authorize.