Build a read-only Context Hub-backed sandbox mount specification.
The repo's latest commit tree is mirrored into mount_path and kept in
sync for the sandbox's lifetime unless initial_pull_only is set. The
sync is one-way: files written under mount_path inside the sandbox are
never pushed back to the repo, and the next sync overwrites them.