I'm using one ssh key per host for my personnal usage, and don't use agent forwarding to prevent that.
At work it's a different story though... I'm part of the team that has root access to all machines, and I don't see why someone would steal my key. Theu can su(1) as me anyway, amd connect to the same machines as me, so it doesn't bother me at all that they can access my auth socket ;)

