Launching a process and invoking a shell are different operations. Prefer argument arrays when input should be data rather than shell syntax.
Before you start
You should know JavaScript promises, asynchronous errors and the distinction between a process and a request. When following a server example, identify the resource owner and the point where work completes. Try experiments locally with bounded input instead of assuming production traffic behaves like a single request.
The practical goal is to reason through this situation: Spawn a known executable with separate arguments instead of concatenating a command string. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Fix the executable
Choose a known program rather than accepting an executable name from uncontrolled input.
Step 2: Pass arguments as data
Use argument arrays without shell interpolation. Validate paths and consider the target program’s own option syntax.
Step 3: Bound the process
Limit input, duration, output and working-directory access. Shell avoidance alone does not authorize arbitrary files.
Worked scenario
Spawn a known executable with separate arguments instead of concatenating a command string.
import { spawn } from 'node:child_process';
const child = spawn('node', ['--version'], { shell: false });
child.stdout.on('data', chunk => process.stdout.write(chunk));
child.on('error', error => console.error(error.message));This harmless example separates executable and arguments. A filename beginning with an option prefix can still matter to the target program, so its argument contract must also be understood.
Common mistake
Shell interpolation can turn user input into executable instructions.
Verify the behavior
Try spaces and shell metacharacters as data in a disposable experiment. Verify argument boundaries and target-program option handling.
Interview exercise
Process an uploaded filename safely.
Answer and reasoning
Validate the path, pass it as an argument and restrict the executable and working directory.
Continue learning
Compare the scenario with the Node.js interview questions and test your understanding with the Node.js MCQs. For terminology and implementation details, consult the reference material.