Local connected backend for the standalone Viewer's run-analysis REPL.
The connected backend owns Core session handles and an idempotent bounded operation ledger. Browser-facing code receives only opaque backend/session references and safe projections; paths and Core capabilities never cross the adapter boundary.