OpenSSH somewhat recently implemented a mechanism to restrict forwarded ssh agents. It may be interesting to look at. https://www.openssh.com/agent-restrict.html