Appearance
Why It Matters
Clipboard contents often include copied secrets, access tokens, passwords, or internal snippets that were never meant to be harvested by shared automation.
What Triggers
SEC687 matches executable hook lines that invoke clipboard-reading utilities such as pbpaste, wl-paste, xclip -o, xsel --output, or PowerShell Get-Clipboard.
False Positives
Shared committed hooks should not read the developer's clipboard as part of normal operation. If clipboard access is truly required for a local-only workflow, keep it out of committed shared hooks.
Remediation
Remove clipboard reads from the shared hook script and require explicit user-provided input instead of harvesting local clipboard state.