* fix(ci): keep the review guidance script free of dependencies
The PR review guidance workflow runs the script with plain Node from the default branch without installing packages, so the Valibot import added with the JSON validation work failed with ERR_MODULE_NOT_FOUND on every review and comment event. The script parses the event and pull request by hand again, accepting the null fields GitHub sends, and a test runs it under Node with nothing installed.
* fix(ci): install the review guidance tool's dependencies instead of avoiding them
Restore the Valibot schemas and declare valibot in the tool's manifest. The workflow now installs the tool's workspace from the default branch's frozen lockfile with the shared setup-bun action and runs the script with Bun. The event schema accepts the null fields GitHub sends for absent values.