The optional `web` extra pins fastapi/starlette in lockstep, but the standalone
starlette security pin ships in several other extras on its own — so a managed
venv can end up with starlette 1.x beside an older fastapi. `hermes dashboard`
then dies constructing `FastAPI(...)` with `TypeError: Router.__init__() got an
unexpected keyword argument 'on_startup'`: not an ImportError, so the module's
own lazy-install fallback never fires, and the process exits before printing a
single line. `hermes doctor` had no probe covering this surface, so a dead
dashboard stayed invisible until the user needed it as a recovery path.
Add a doctor check that imports `hermes_cli.web_server` in a subprocess with
lazy installs disabled (read-only probe; it must never repair what it is
diagnosing) and reports the failing line plus the repair hint, or a soft warn
when the optional web extra is simply absent.
Fixes#124214