Signatures are safe to post. They don't contain private data and ultimately are the result of a one-way hash function. So unless an unsafe hash algorithm is used (e.g. SHA-1), signatures are safe. (Even with a SHA1 hash it's safe to post, just not safe to use any longer due to too high chance of collisions.)
Personally, I'm still not convinced it's necessary for CAs to make sure any posted private key can't be used on their system even if there isn't a certificate associated with it. If that's the case, I wish the LE team good luck (sincerely! as it's probably quite labor intensive) with indeed revoking all the private keys posted on this Community (there are A LOT).
EDIT!:
It seems 6.1.1.3 does actually mandate this! Although one can argue what the confines of "made aware" is:
The CA SHALL reject a certificate request if one or more of the following conditions are
met:
(…)
4. The CA has previously been made aware that the Applicant’s Private Key has
suffered a Key Compromise, such as through the provisions of Section 4.9.1.1;
So if a LE crewmember does come across a private key, that indeed would mean that the CA SHALL make sure that key can't be used any longer, such as revoking a randomly generated cert and subsequently revoking it, with keycomprimise as reason.
My initial BR search did not find this paragraph, my apologies to James for doubting. Although this does maybe present a problem with all the private keys posted on the Community. Is "made aware" only when an actual crew member comes across the private key or is posting it on the Community "made aware" enough?
If I understand James post correctly, even randomly generated keys which are not intended to be used for anything at all need to be revoked.
So with or without mentioning "test key".