I don't live in fear of that risk myself, because that isn't how HiveSigner works.
When you login to Hivesigner, your private key is available within the interface to sign transaction and message, keys never leaves the browser. We never have access to your private keys
All these tools basically pass your information through to the chain and leave it at that, and in the past I used to audit new keytools for Steem back in the day, but I sort of quit doing that because no significant new ones showed up for a long time, then when they did, they came from some of the most well-known, "esteemed" code creators in the ecosystem so there wasn't too much to worry about.
But I do have concerns when I am asked to enter my keys into an unknown entity and as we grow, there will surely be more unknown entities and nefarious actors in the mix.
It's right to be cautious, but it's also generally possible to know if you are giving your keys to someone who will retain them and know them or not, by investigating how their signing processes actually work.
Of course, that can take some technical know-how or trust in the keychain manufacturer so yeah, it's a tough situation, that's why I made the poll :)
Thanks for answering it!
RE: HiveSigner, Hive Keychain, HiveAuth or Enter Your Key On A Site??? (later entry: PeakLock - see update inside about that oversight)