Yes. If someone has your private key they can sign commits as you. I’m not sure how I can put this more plainly.