Appearance
Why It Matters
An MCP launcher that reads the local clipboard can silently extract copied secrets or internal data whenever the tool is invoked.
What Triggers
SEC689 matches committed MCP command paths that invoke clipboard-reading utilities such as pbpaste, wl-paste, xclip -o, xsel --output, or PowerShell Get-Clipboard.
False Positives
Committed MCP launchers should not rely on hidden clipboard access. If clipboard input is really needed, it should happen through explicit user interaction rather than a shared committed command.
Remediation
Remove clipboard reads from the committed MCP launch path and require explicit input instead of harvesting local clipboard state.