If Facebook made use of smart OCAP practices, none of that would be possible. Use of object identity as a "security key" would prevent code that doesn't have access to the "key" object from being successful.
document.getElementsByTagName('script')[0].innerText > fn = function(){ var key = "shhhhh" }
> fn.toString()
'function (){ var key = "shhhhh" }'
Nothing is sacred in JS.But it requires that the value is hardcoded inside the function. If it was given to an unreachable scope by some async action (like an ajax request) this trick wouldn't work.
One could possibly also wrap the function in an native .bind call to change the output of toString() to [native code]
It's better to assume the console has 100% root (client-side) privileges.