Architecture and design: Prefer library calls over external processes when they can provide the required functionality. Implementation: Keep externally invoked commands statically defined whenever possible. Treat all input as malicious and apply strict allowlist, or accept-known-good, validation covering length, type, allowed values, missing or extra fields, syntax, consistency, and business rules. Do not rely only on denylists or searches for known malicious patterns; denylists can still help detect suspected attacks or reject clearly malformed input. Runtime and configuration: Enforce an allowlist of sanctioned commands at runtime and assign permissions that prevent users from accessing or opening privileged files.