shell=False Is a Small Setting with a Large Security Boundary
Passing an argument array directly to exec avoids an entire class of shell expansion and injection behavior.
Passing an argument array directly to exec avoids an entire class of shell expansion and injection behavior.
Keeping host execution outside the portal containers limits what a web compromise can directly control.
A safe command can still become unsafe operationally if it can occupy the runner forever.