Am I missing something? This isn't a vulnerability. Your agent can see the files in its virtual environment. SSH keys are also not necessarily confidential. Please don't use AI to write blog posts.
If the only purpose of the sandbox were to isolate the instance of the service the user used then it might be a different expectation.