Appearance
Why It Matters
Committed plugin hooks execute in developer environments and should not silently harvest clipboard data that may contain secrets or internal material.
What Triggers
SEC693 matches committed plugin hook command values that invoke clipboard-reading utilities such as pbpaste, wl-paste, xclip -o, xsel --output, or PowerShell Get-Clipboard.
False Positives
Shared plugin hooks should not depend on hidden clipboard reads. If a workflow needs pasted input, it should require an explicit user action instead.
Remediation
Remove clipboard reads from the committed plugin hook and require explicit input instead of harvesting local clipboard state.