For example, in Python you could easily do this:
message = '; cat /etc/passwd'
# Whoops, shell injection vulnerability!
subprocess.run(f'echo Message: {message}', shell=True)
# Correct (assuming sh-compatible shell).
subprocess.run(f'echo Message: {shlex.quote(message)}', shell=True)
# Correct (without using shell).
subprocess.run(['/bin/echo', 'Message:', message])
But the Bun API doesn't separate quoting from executing the command, so you can't make that kind of mistake: let message = '; cat /etc/passwd';
// Works correctly.
await $`echo Message: ${message}`.text();
// Fails safely by throwing error about incorrect usage.
await $('echo Message: ' + message).text();