I think it is important to point out what 1Password’s Secret Key in meant to do. From 1Password’s website:
“Your Secret Key protects your data off your devices. Someone who attempts a brute-force attack on our servers won’t be able to decrypt your data without your Secret Key, which we never have.”
Note that the Secret Key wouldn’t help protect your data if your device is stolen.
I think the Secret Key feature is a great idea, but I also believe this is far more important for those who choose to put their vaults on servers rather keeping them local.
Yeah, if a device is unlocked then the thief would only need to use the master password. However, I'm not sure how they would launch a brute-force attack against that master password using that device. I suspect they would move the vault to another platform for that and then the secret key would be in their way.