The R720 box has no gh installed, so the draft-PR monitor's `gh pr list`
shell-out raised FileNotFoundError on every 30s tick and the monitor was
permanently blind to open draft PRs (no runaway/stale detection). The
dispatcher already authenticates with a short-lived App installation
token over REST; reuse that path.
Add app_draft_pr_lister (GET /repos/{owner}/{repo}/pulls, client-side
filter to draft PRs under agent-team/apply/) and prefer it in the monitor
provider when AGENT_TEAM_GH_APP_* are set, falling back to gh otherwise.
Fails soft to an empty snapshot so a sweep never crashes the tick loop.
The builders node accepted any non-empty diff string and advanced it to
dispatch. Two failure modes seen live slipped through: a diff with
placeholder hunk headers (`@@ -X,Y +A,B @@`) that git apply rejects with
exit 128 (the task then parked at dispatch with an opaque error), and a
no-op empty-file creation that applied cleanly and opened a blank draft PR.
Add a pure, deterministic shape check in build_candidate_diff that fails
with an actionable BuildError when a hunk header is non-numeric or the
patch carries no added/removed content, so the cause surfaces at build
instead of downstream.