If it's a standard ecash token then yes you should be careful with pasting the token into any online form. Feel free to download the code and run it offline if you wish. Dont trust. Verify. 👍
If it's a P2PK ecash token then it won't matter because only the recipient can redeem. Good questions.
As for the Meshtastic app copy/paste issue, it's just kind of clunky and the copy button (at least on Android) doesn't work as expected.