if unconfined, the number of ways a desktop app can spy on the user is infinite. If the clipboard specifically is a concern, you can always use autotype functionality.
Also, things like https://discuss.privacyguides.net/t/zero-day-clickjacking-vulnerabilities-in-major-password-managers aren’t possible with desktop password managers