Two operators, no subprocess
ProofFrameAcceptOperator scans a file against a contract inside the worker, so the library's exception types survive and the engine's own memory and temporary-storage limits are the ones that apply. ProofFrameVerifyOperator checks a bundle another task produced, and rescans nothing.