Leaking system prompts being classed as a vulnerability always seems like a security by obscurity instinct.
If the prompt (or model) is wooly enough to allow subversion, you don't need the prompt to do it, it might just help a bit.
Or maybe the prompts contain embarrassing clues as to internal policy?