This seems like it’s barely a bug. Of course the files in the agent environment are not secret.
It's also the files and utilities, which tells you the versions, if they contain CVEs, if there are undocumented services running which could be exploited and so on, and as he mentioned also SSH keys (unclear if the private keys, but even public keys are interesting because they can tell you the names of internal developer machines).
quite literally the fifth sentence:
>There were also SSH key files.
Exfiltrating many binaries gives you the right to their source code, or at least triggers attribution requirements for licensing compliance.
But perhaps Meta did the smart thing and put the source code into the VM, too. That would be a very reliable indicator that they expected exfiltration, and this is in fact working as intended.