Can't this be used to poison the clipboard with bad code that once pasted in the wrong place will execute?
But Mozilla just re-enabled this exploit and I don't think it can be turned off.
User-initiated != user-approved, at least not unless the user is specifically asked. (Like by, say, prompting allow/allowalways / deny / denyalways)