On findings the scan now POSTs a high-priority notification to topic
st_security on the host ntfy (127.0.0.1:2586), authenticated with the
si_17t_pro token read from /etc/ntfy/credentials/auth.env (never logged).
Topic/cred/URL overridable via env for testing.
Periodic host+container sweep for the exact indicators seen in the staging
miner incident: decoy process names (redis-server/kworkerd/xmrig/ssl_client/
init.sh), /tmp/.kworkerd and .redis-server.pid artifacts, and high-CPU
containers. Findings are logged and exit 1 for cron MAILTO alerting.
Closes MITHOME-82