we should probably have a command to check whether a shadowenv is trusted by the current key.
we should probably have a command to check whether a shadowenv is trusted by the current key.