How specific should except clauses be?
Specific enough that an unexpected failure still crashes. except Exception around an entire request handler is fine if it logs and re-raises in development; the same clause around three lines of parsing will swallow the typo that broke them.
Where do you start adding type hints to an existing project?
At the boundaries: function signatures on public modules first, internals never. Run the checker in non-blocking mode for a few weeks so the noise is visible without stopping anyone, then turn on strictness one module at a time.
Is shell=True ever acceptable?
When the command genuinely is a shell pipeline you control end to end, and never with any value that came from outside the program. The list form avoids quoting entirely, which is both safer and easier to read.
What is the most common way people get this wrong?
Doing it once and never verifying. The setup is the visible part, so it gets attention, and the check that would catch a silent failure never gets written.