There's nothing magical with the passkeys, they're just like ssh keys. Their main advantage is that by doing asymmetrical cryptography you don't just hand over your secret (password) to someone, so you don't care if somehow you're talking to the wrong site, you don't even need to rotate your credentials if they get genuinely hacked.
Protecting them locally is of secondary importance, but if you wish to be locked behind a password only you know in your password manager (most good ones nowadays do passkeys too) you can do that too.
Also, if we're talking about being compelled legally - these aren't for giving you access to some encrypted vault you only have access too - they can be shoehorned into all kinds of cryptographic things but not as the main use case. The main use case is just to login to Gmail, Paypal, Github, Cloudflare, whatever. If "they" are investigating you they can get to all those accounts without asking you, often even preventing the provider from telling you they gave away your data.