I imagine a very large proportion of identity theft attacks involve some sort of social engineering at one point or another and that passkeys (the concept is not even very clear) will not prevent that…
If you're suggesting by social engineering that a user is in some way tricked to disclosing credentials though perhaps a phone call or email, or a dodgy website link, then all of those mechanisms will be thwarted by passkeys.