Address security-review F1/F3: the workflow re-check used a POSIX
[[:cntrl:]] grep (missed the C1 range the box-side sanitizer strips) and
wc -m (byte count, not chars). Replace both with a single python3 check
whose accept condition is byte-for-byte identical to sanitize_pr_title —
rejects [\x00-\x1f\x7f-\x9f] and caps at 70 characters — so the
defense-in-depth re-validation genuinely matches the box path.
Address cross-review FIX: the title re-validation used GNU-only
`grep -P`. Switch to POSIX `[[:cntrl:]]` under LC_ALL=C so the check
is portable; C1 chars are already stripped box-side by sanitize_pr_title.
The apply pipeline's draft PRs were titled `agent-apply: <task_id>
(diff <hash>)` with a flat body — neither within Sea Haven PR
conventions. That format was deliberate injection-hardening (only
sanitized tokens, never model free-text; §4.6).
Thread the approved plan's title through dispatch as an optional
`pr_title` input, sanitized box-side (single line, no control chars,
70-char cap, capitalized) and RE-VALIDATED in the workflow as defense-
in-depth, with the hardened `agent-apply: <task_id>` title as the
fallback when empty/unsafe. Provenance (task id, diff hash, head) moves
to the PR body. gh consumes both as argv data, never shell-interpolated.