Take the recent example of Copy/Fail (CVE-2026-31431) if you were to evaluate it against your k8s seccomp and noticed that the argument to the syscall socket of AF_ALG is not allowed, then the vuln is not reachable in your pods.
I’ve not used this tool (I plan to check it out), but I think contextual evaluation of CVEs is important in modern times.