node-execa is the last reverse dependency of node-cross-spawn. It looks like execa doesn't use risky features of cross-spawn but uses it to parse command line. Suggestion: embed cross-spawn in node-execa and ROM-RM node-cross-spawn