That makes user attacks possible as subprocess can't quote arguments correctly. https://github.com/kbaseapps/kb_uploadmethods/blob/86bf252c38a7895396ec2b85a1fb67d322f1da6e/lib/kb_uploadmethods/Utils/ImportSRAUtil.py#L60-L61