As noted in other comment(s), there are legit uses for this.
And to be clear, I'm talking about providing at least one legit use for passing user input directly to exec without any kind of filtering...
He deliberately wrote vulnerable code to test his auditing script. There are more repos like this.