Thanks for this!
Eric Anderson
2

You’re in a much more dangerous position using copy/paste rather than using the 1password extension.

Any code running on your mac can access the clipboard without your consent, whereas accessing 1password data at least requires a very lucky set of circumstances if they’re pretending to be 1password mini (Detailed here by 1password in June 2015: https://blog.agilebits.com/2015/06/17/1password-inter-process-communication-discussion/)

Or, if they want to use the way this medium post describes, you need elevated permissions, at which point they could do all manner of bad things (like installing malicious browser extensions which mean your copy/paste or even 1password encryption is completely useless, as the interception would take place after decryption, or paste!)