The following scenario is sensitive in a business environment: An employee logs into Thunderbird with the master password. Once entered, it becomes possible for the employee (or others using the same computer) to make copies of secret PGP keys.
Proposal: Exporting secret keys should only be possible through the input of an additional, separate password.
Furthermore, it would be advisable not to protect stored passwords for email accounts with the master password but also with a separate password.
Regards,
Ranger68