Appearance
Why It Matters
Committed plugin hooks execute in developer environments. Reading and transmitting clipboard contents from them is a strong signal of local secret theft.
What Triggers
SEC701 matches committed plugin hook command values that combine clipboard-reading utilities such as pbpaste, wl-paste, xclip -o, xsel --output, or PowerShell Get-Clipboard with remote sinks such as curl, wget, scp, rsync, nc, or HTTP(S) endpoints.
False Positives
Shared plugin hooks should not read and transmit clipboard contents. If a workflow needs pasted input, it should require explicit user action instead.
Remediation
Remove network exfiltration of clipboard contents from the committed plugin hook and require explicit input instead of harvesting local clipboard state.