What's insecure about curl and mkdir?
Say that you have a website that relies on downloading content from URLs supplied by users. A user can send a "specially constructed" URL ("anything;commandgoeshere") and run any command they'd like on your server.