Source code is not the whole runtime.
Effective model routing, project instructions, MCP capabilities, sandbox policy and runtime versions can change independently. Looking only at the repository answers what was written, not necessarily what the agent actually resolved and can use.
Model and provider
Workspace configuration can leave values unset while the runtime resolves a concrete effective model and provider when work starts.
Instructions
Project instruction files can change without application code changing. Their source paths and fingerprints are part of the effective runtime identity.
Capabilities and permissions
Sandbox/network policy and the MCP capability surface determine what an agent can actually reach and do.