Your quoting of "$0" does not protect it from the shell. An attacker need only provide an input such as: /tmp"; rm -rf /; "
There are pipeline libraries that avoid the shell for several languages. Some I can recommend:
* libpipeline http://libpipeline.nongnu.org/ easy, if somewhat verbose, pipeline construction in C.
* hsh https://github.com/jgoerzen/hsh/wiki makes pipelines in haskell, using operators so they really look like pipelines, but without involving the shell. Example: "ls -l" -|- "wc -l"