Hm. What mechanism does password managers like Onepass and Lastpass use?
I assume (hope) the others do it the same way. Clipboard memory has _never_ been safe not on PC and not on phones.
[0]. https://play.google.com/store/apps/details?id=keepass2androi...
Keepass for windows and linux use autotyping or clears the buffer after a few seconds if you copy.
Treat your phone like you've always treated your desktop - only install trusted applications and use tools like XPrivacy to analyze sketchy applications and block "features" for the ones you absolutely need to use.
Maybe I'm wrong, but at the very least, XPrivacy indicates it accesses clipboard shortly after requesting auto-fill - don't have a hook for setting text there.