Skip to content
← All rules
SecurityInjection

security/no-untrusted-command-execution

Prevent direct same-function flows from request data to shell, command, or dynamic-code execution unless executable and arguments are visibly constrained.

commandsshelluntrusted-input
TypeScript
exec(`convert ${req.body.file}`);
Finding

Disallow request data reaching command or code execution.

Setup

Install the package, register its plugin factory, then enable the rule.

Install the package

pnpm add -D @scruple/security

Register the plugin

In scruple.config.ts, register the factory under the security namespace used by the rule ID.

import { security } from "@scruple/security";

plugins: {
  "security": security(),
},

Enable the rule

"security/no-untrusted-command-execution": "warn"
Package
@scruple/security
Default threshold
0.9
Minimum confidence
0.75

Released under the MIT License.