Its just that its not Facebooks place to do this. I wouldn't expect a app linux binary to upload the contents of /usr/lib, or a windows app to start sending system32 dll's off system.
FB can try to sell this as a 'lite-AntiVirus' type service, but that is not its place. There is no indication the app is doing this. Its FB being creepy as usual.
If Google did it, it would be less creepy, just like how Microsoft can grab malicious files detected by Defender -- but they write, support and protect the OS! FB is just an app. It shouldn't be harvesting its users operating system files!
Google's SafetyNet scans the system files, but it looks for _specific_ files that should not be there and ensures that certain files that must remain unaltered actually remained unaltered to ensure that the security model is still intact, so it doesn't need to violate copyright laws by stealing copies of files off the user's phone without permission or user awareness.
...and funny that you mention Windows Defender because it repeatedly advises the user that it might upload files to Microsoft and asks for their approval for doing so at multiple points. Microsoft is being perfectly transparent about what they're doing and giving users the ability to opt-out. They're also the people who make the entire operating system so they've got an obligation to try real hard to prevent another Blaster incident. Facebook just makes a social media app.
This is the biggest one for me. Anyone who has that data is capable of playing back the 0-days that affect android. How many android phones are kept out of date?
As other user mentioned, the Android ecosystem is like the Wild West. Given there's a report for 2.5B active devices, how many can be affected by such an attack?
1% would affect 25M devices, around the population of Australia. 10% - 250 million devices. 40% - 1 billion devices...