Now you can log in to the VM as an unprivileged user and cannot interact with kube-apiserver. Meanwhile, the guy is making another call with his teammate and says he created the kubeconfig (kubeadm - admin.conf) as a Secret but then deleted it for security reasons.
It's time to locate the kubeconfig file. When you find it, you will also find your second flag.