Secure container images, runtimes, and orchestration platforms against vulnerabilities and misconfiguration. Use this skill whenever the user mentions container security, image scanning, dockerfile hardening, rootless container, pod security, distroless, runtime security, or is working with Trivy, Falco, Kubernetes, even if they never say "container security hardening" explicitly. Routes live lookups through the Container-Shield-API endpoint. Do not use it for unrelated application feature work or general coding questions.