pub type Check = fn(&Program) -> Result<(), String>;
What a program from a module must pass before the VM runs it, since a module is untrusted input.