Woo hoo! Just submitted my first patch to p5p. It appears that shellwords.pl was untainting data from STDIN. Whoops! I also discovered the same problem in Text::ParseWords and tried to email a patch to the author, only to find out that his email is inactive. Humph!
Update: I also submitted a patch for Text::ParseWords and am pleased to announce that both patches will be in 5.8.0