If you're copy-pasting passwords from 1password into your browser you're making yourself vulnerable to phishing. The browser extension's autofill will at least check the domain name and prevent that.
This would be possible via attestation, but both Apple and Google removed that feature when they replaced their respective device-bound authenticator implementations with cloud-synchronizing ones. (Google technically still allows creating device-bound ones and supports attestation in that case, but that's arguably a niche use case and not what people are talking about when they say "passkeys".)