Yes, that's the common rebuttal. It's resistant to MITM and phishing, but it's still not two-factor.
If you store your passkey on a yubikey with PIN, I suppose it's two-factor in the sense that you need the key and a PIN, but you can only store so many passkeys that way.
Is it just that more is better?
Traditional server-side 2FA (e.g., "give me a password and a 1-time code") is superfluous in a passkey world, because it's ultimately just a hack to make up for the fact that password-only auth is weak. Key auth is incredibly strong, so a server-side 2FA challenge doesn't buy you much.
Put all of your passkeys in a single repo (as most people will), and you're literally putting all of your eggs in a single basket. Better hope nobody gets ahold of that basket.