There's a CLI for 1Password in beta - https://app-updates.agilebits.com/product_history/CLI
Perhaps it'd be possible to automatically add the generated APP_KEY to a vault? 😍
Something like composer create-project oddhill/drupal-starter-kit ./project-dir --stability dev --no-interaction --1password-vault "Our shared vault"
Don't know if the CLI supports everything we need yet though.