Yeah, a developer owning a YubiKey and using a password manager, that's really revealing...
Unless you're in for the criminal acts (and their repercussion), i.e., stealing my token and my keys to wherever my workstation stands and then torturing out both, my workstations and key's PW from my mind, it won't really help you...
Or what did I really reveal with what actual real world implication that can compromise the security of (which?) systems I can access?
IMO, if your "security pipeline" can be compromised due to documenting it (not the credentials used to access it!), even publicly, it wasn't that good of a "security pipeline" in the first place.