So the answer is to paste it into an editor first?
Not only is this a good habit as far as security goes, it's also the best way I can think of to learn from problems.
Because they can put a newline in the malicious paste.
[1]: At least, in the terminals I regularly use.
I then put sample command line in HTML, with an embedded  . Yep, copied and pasted just fine.
Which means my SOP for dealing with untrusted text isn't anywhere near as good as I thought it would be.
Thanks for pointing that out!