---
url: https://scruple.dev/rules/security/no-untrusted-command-execution.md
description: Disallow request data reaching command or code execution.
---

# security/no-untrusted-command-execution

Disallow request data reaching command or code execution.

## What it checks

Prevent direct same-function flows from request data to shell, command, or dynamic-code execution unless executable and arguments are visibly constrained.

## Rule metadata

* Package: `@scruple/security`
* Category: Injection
* Tags: commands, shell, untrusted-input
* Default threshold: `0.9`
* Minimum confidence: `0.75`

## Examples

### Reported

```ts
exec(`convert ${req.body.file}`);
```

### Accepted

```ts
execFile("convert", [allowedFiles.get(req.body.file)!], { shell: false });
```
