Specifically the key ID isn’t signed so if you’re sharing private keys, someone who captures a signed message can just swap key IDs
Capturing a signed message sounds hard but if you do manage to do it you can probably e.g. read private posts accessible to anyone on your instance
So its probably not an issue for mostr because that’s a bridge to libertarian hellscape where everything is public all the time but in general I dunno the security calculus is nontrivial