This doesn't seem materially different from "please go to your emails and find the six-digit code we just sent you".
> Exporting a passkey leaves no relying-party-side traces.
Not if it's only useful for getting a device-bound session token. Everything you listed is already commonplace.