Pull every file path out of the current file in one keystroke
JavaScript, TypeScript, JSON, YAML, HTML, CSS, TOML, CSV and Environment files β and every other file, by text scan
Useful? A star or rating is how other developers find it β
β
GitHub Β·
β
Open VSX Β·
β
Marketplace
What it does
Open a file, run Paths-LE: Extract Paths, and every file path in the document lands in a new editor β deduplicate and sort it from there. Works in VS Code and in VS Codeβbased editors like Cursor and VSCodium (installable from Open VSX).
- Import analysis β extract local imports from JS/TS, including multi-line import statements; npm package names are filtered out
- Asset auditing β every
src, href, srcset, url(), and @import in HTML/CSS
- Config review β path-like values from JSON/JSONC, YAML, TOML, CSV, and
.env files
- Anything else β Python, Go, Markdown, XML, a Dockerfile: no parser, so a text scan finds quoted filenames and any run carrying a path separator
Install
| Where | What you get | Install |
|---|
| VS Code | The extraction, in your editor, on a keystroke | Marketplace |
| Cursor, VSCodium, Windsurf | The same extension | Open VSX |
| A terminal or a CI step | The same run over a whole tree, with exit codes | cargo install paths-le Β· crates.io |
| Any MCP agent, via Node | extract_paths over stdio β the same tool this binary offers | npx paths-le-mcp Β· npm |
Use it from an AI agent
The same engine runs as an MCP server, so an agent can call it directly instead of you running a command.
| Editor | How |
|---|
| VS Code 1.101+ | Nothing to install β the extension registers extract_paths with agent mode |
| Claude Code | claude mcp add paths-le -- npx -y paths-le-mcp |
| Cursor, Windsurf, anything else | point it at npx paths-le-mcp |
extract_paths(content, format?, filename?, dedupe?, maxResults?)
Returns every path classified as file, relative, absolute or url, with its 1-based line and column. Paths are reported exactly as written β nothing is resolved against a workspace or touched on disk.
The server takes content and returns data β it reads no files and makes no network requests of its own. Published as paths-le-mcp on npm and as io.github.nolindnaidoo/paths-le in the MCP registry.
Configuring it by hand β any host with an MCP config file
Most hosts read a JSON config. Add one entry:
{
"mcpServers": {
"paths-le": {
"command": "npx",
"args": ["-y", "paths-le-mcp"]
}
}
}
-y skips the install prompt on first run. Pin a version if you would rather not track releases β paths-le-mcp@2.4.0.
Prefer not to go through npx on every launch? Install it once and point at the binary instead:
npm install -g paths-le-mcp
{
"mcpServers": {
"paths-le": { "command": "paths-le-mcp" }
}
}
It speaks MCP over stdio and needs no environment variables, no API key and no configuration of its own. To check it before wiring it into anything:
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' | npx -y paths-le-mcp
That prints the tool list and exits β if you see extract_paths, the server works.
Across a folder or a workspace
Extract reads the document you have open. A scan reads many files from disk and gives one report.
- The whole workspace: run
Paths-LE: Extract Paths from Workspace from the command palette.
- One folder: right-click it in the Explorer and choose
Extract Paths from Folder, or run Paths-LE: Extract Paths from Folder and pick one.
A project writes the same path in many places, so the report is the distinct paths, the most widely used first, with how often each is written and where:
# Paths-LE workspace report
`my-project` Β· 4 file(s) read Β· 2 distinct path(s), 4 occurrence(s) in 3 file(s)
| Path | Occurrences | Files |
|---|---|---|
| `./lib/util` | 3 | 2 |
| `./config/app.json` | 1 | 1 |
## `./lib/util` (3)
- `src/a.ts` Β· **1:20**, **2:20**
- `src/b.ts` Β· **1:20**
## `./config/app.json` (1)
- `deploy.json` Β· **2:14**
## Could not be read (1)
- `bad.csv`: Invalid CSV: quoted field is never closed (row 1, cell 2)
That is with paths-le.showPositions on. It is off by default, and then each line is the file and how many times the path is in it: src/a.ts (2). The copy on the clipboard follows paths-le.clipboardIncludesPositions, as it does for Extract.
A file its format reader refused is listed with the reason, never passed over. A malformed CSV that holds a path is not the same as a file that holds none.
A scan reports each path as written. It does not resolve symlinks or workspace-relative paths, whatever the resolution settings say: those describe one document on one machine.
What a scan reads. Files come from disk, so an unsaved edit is not seen. A file over the safety size, or one that is not UTF-8 text, is left unread. It stops at 5,000 files or 10,000 listed occurrences. The report ends with a line for each thing it left out, so a short report is never mistaken for a clean project.
What it skips, and how to change that. Three switches are on by default, and each can be turned off on its own in Settings:
| Switch | Skips |
|---|
scanUseDefaultExcludes | Dependency folders, build output, tool caches and lockfiles. The full list is below |
scanRespectGitignore | Whatever the project's .gitignore files skip |
scanSkipBinaryFiles | Images, fonts, archives and other files that are not text |
Two lists adjust the result without turning a switch off. To skip more, add a pattern to scanExcludes. To read something a switch would skip, add it to scanAlwaysInclude:
{
"paths-le.workspace.scanExcludes": ["**/fixtures/**"],
"paths-le.workspace.scanAlwaysInclude": ["**/vendor/**"]
}
Paths-LE: Open Settings opens all of these in the Settings editor.
The built-in list
Folders, wherever they appear:
.git, .hg, .svn, node_modules, bower_components, jspm_packages, .pnpm-store, .yarn, vendor, site-packages, Pods, Carthage, dist, build, out, target, _build, _site, dist-newstyle, zig-out, storybook-static, cdk.out, DerivedData, CMakeFiles, .next, .nuxt, .output, .svelte-kit, .angular, .astro, .docusaurus, .vuepress, .expo, .turbo, .parcel-cache, .cache, .sass-cache, .jekyll-cache, .dart_tool, .pub-cache, .gradle, .kotlin, .cxx, .externalNativeBuild, captures, ephemeral, .symlinks, .swiftpm, .build, .bundle, .stack-work, .zig-cache, .godot, elm-stuff, .vercel, .netlify, .serverless, .aws-sam, .terraform, .venv, venv, __pycache__, .tox, .nox, .mypy_cache, .pytest_cache, .ruff_cache, .ipynb_checkpoints, .eggs, coverage, htmlcov, .nyc_output, .vscode-test, .idea, .vs, xcuserdata, *.egg-info
Files, wherever they appear:
*.min.js, *.min.css, *.map, *.snap, *.lock, package-lock.json, pnpm-lock.yaml, npm-shrinkwrap.json, go.sum, *.pbxproj, *.iml, local.properties, output-metadata.json, .flutter-plugins, .flutter-plugins-dependencies, .packages, Generated.xcconfig, flutter_export_environment.sh, GeneratedPluginRegistrant.*, fastlane/report.xml, fastlane/test_output/**, doc/api/**
Not on the list, because they are ordinary folders in many projects: bin, obj, tmp, logs, public, generated. A project that generates those ignores them in git, and the scan reads .gitignore.
The settings that shape a scan are under Settings.
The CLI
The same extraction runs from a terminal or an agent loop: a Rust CLI in
crate/ of this repository, sharing one corpus with the extension β
crate/fixtures/ β so CI fails if the two ever read a
document differently.
It also does the half an editor cannot: resolve what it found against the
filesystem it is standing in. Every path gets a verdict β exists, missing,
escapes the audited tree, non-canonical, or a symlink with its target named.
paths-le .
paths-le --strict .
paths-le --no-resolve src/
paths-le mcp
The exit code is the answer: 0 clear Β· 1 findings Β· 2 the question was
malformed β so paths-le --strict . is a CI step as it stands.
| Format | Language IDs | What gets extracted |
|---|
| JavaScript / TypeScript | javascript, javascriptreact, typescript, typescriptreact | import/export β¦ from, side-effect imports, dynamic import(), require() β file paths only, package names excluded |
| JSON / JSONC | json, jsonc | Path-like string values (comments and trailing commas supported) |
| HTML | html | src, href, srcset (each entry), action, poster, and similar attributes |
| CSS / SCSS / LESS | css, scss, less | url() and @import |
| TOML | toml | Path-like values and keys |
| CSV | csv | Path-like cells |
| Environment | dotenv, env | Path-like variable values and names |
| YAML | yaml | Path-like scalar values and keys, across every document in the file |
| Everything else | any other language ID | A text scan: quoted tokens, and undelimited runs that carry a path separator |
Positions are real source positions for JS/TS, JSON/JSONC, HTML, CSS and the text scan (exact line and column of the path); TOML and YAML positions are located in the source text and can be approximate for repeated identical values; CSV positions are row/cell coordinates. Version strings (1.8.1) and IP addresses are never treated as paths, and data:/javascript: URLs are excluded from HTML/CSS extraction. Bare domains (example.com, www.example.org) are not paths; a name ending in a country-code extension such as docs.rs still is.
The text scan claims a bare name.ext only inside quotes. os.path in a Python file and main.py are the same shape, and no rule short of a dictionary separates them β but source quotes its filenames and does not quote its attribute access, so the quoting does. A YAML scalar holding a shell command (run: node ./scripts/build.js) is one token containing spaces, so no path is claimed from it, exactly as in JSON and TOML.
Commands
| Command | Description |
|---|
Paths-LE: Extract Paths | Extract all paths from the active document |
Paths-LE: Extract Paths from Workspace | The distinct paths in every file in the workspace, and where each one is |
Paths-LE: Extract Paths from Folder | The same for one folder. Also on a folder in the Explorer |
Paths-LE: Deduplicate Paths | Remove duplicate lines from the results |
Paths-LE: Sort Paths | Sort results alphabetically or by length |
Paths-LE: Open Settings | Open Paths-LE settings |
Paths-LE: Help | Built-in documentation |
No command is bound to a key by default. Give any of them one under Keyboard Shortcuts in the editor.
Settings
| Setting | Default | Description |
|---|
paths-le.openResultsSideBySide | true | Open results beside the current editor |
paths-le.postProcess.openInNewFile | true | Open results in a new file (when not side-by-side) |
paths-le.showPositions | false | Show the line and column of each path |
paths-le.copyToClipboardEnabled | false | Also copy results to the clipboard |
paths-le.clipboardIncludesPositions | false | Include the line and column in that copy |
paths-le.notificationsLevel | silent | all = every notification, important = warnings + errors, silent = errors only |
paths-le.workspace.scanPatterns | ["**/*"] | The files a folder or workspace scan reads |
paths-le.workspace.scanUseDefaultExcludes | true | Skip dependency folders, build output, caches and lockfiles |
paths-le.workspace.scanRespectGitignore | true | Skip what the project's .gitignore files skip |
paths-le.workspace.scanSkipBinaryFiles | true | Skip images, fonts, archives and other files that are not text |
paths-le.workspace.scanExcludes | [] | More files to skip, as glob patterns |
paths-le.workspace.scanAlwaysInclude | [] | Files to read even when one of the three above would skip them |
paths-le.workspace.scanMaxFiles | 5000 | The most files one scan reads |
paths-le.workspace.scanMaxResults | 10000 | The most occurrences one scan lists before it stops reading |
paths-le.safety.enabled | true | Guardrails for very large files |
paths-le.safety.fileSizeWarnBytes | 1000000 | Refuse extraction above this file size |
paths-le.safety.largeOutputLinesThreshold | 50000 | Warn above this line count |
paths-le.statusBar.enabled | true | Show the status bar item |
paths-le.telemetryEnabled | false | Local-only event log (see Privacy) |
paths-le.resolution.resolveSymlinks | false | β οΈ Resolve symlinks to canonical paths |
paths-le.resolution.resolveWorkspaceRelative | false | β οΈ Resolve paths against workspace folders |
Languages
Twelve languages besides English:
German Β· Spanish Β· French Β· Indonesian Β· Italian Β· Japanese Β· Korean Β·
Portuguese (Brazil) Β· Russian Β· Ukrainian Β· Vietnamese Β· Chinese (Simplified)
Both halves are covered β the manifest (command titles, setting names and
descriptions) and everything shown while the extension runs (notifications,
the status bar, quick-picks and prompts). The extension follows VS Code's
display language, so it matches whatever the editor is already set to; no
setting of its own.
Privacy & security
- No network access. The extension never sends data anywhere. The
telemetryEnabled setting only writes events to a local Output Channel you can inspect (Paths-LE Telemetry).
- Canonical resolution is opt-in and warned. Resolving symlinks/workspace-relative paths can put absolute filesystem paths into the results document; the extension warns before first use. Leave both
resolution.* settings off unless you need them.
- The MCP server holds the same line. It takes content as an argument and returns data: no filesystem access, no network calls, no telemetry. Your agent already has file-read tools, so duplicating them inside the server would add a path-traversal surface for no capability.
check:mcp-bundle fails the build if the server ever imports something that could reach either.
- Error notifications redact home directories and credential-shaped fragments.
- One rating prompt, at most twice. On the 3rd successful use the extension asks once whether you would rate it, and once more on the 20th if you chose Later or dismissed it. Don't Ask Again ends it. Setting
notificationsLevel to important or silent yourself turns it off. The counts are kept in VS Code's extension storage and nothing is sent anywhere; Rate opens the listing you installed from β the VS Code Marketplace or Open VSX β in your browser.
Documentation
| Input | Size | Found | Time | Rate | Scan speed |
|---|
| TypeScript imports | 2.10 MB | 40,000 | 19.85 ms | 2,015,130/sec | 105.9 MB/s |
| JSON config | 1.17 MB | 40,001 | 23.17 ms | 1,726,103/sec | 50.6 MB/s |
| HTML document | 1.27 MB | 40,000 | 18.64 ms | 2,146,436/sec | 67.9 MB/s |
| CSS stylesheet | 1.57 MB | 40,000 | 16.47 ms | 2,428,210/sec | 95.3 MB/s |
| CSV data | 2.09 MB | 60,000 | 67.22 ms | 892,581/sec | 31.1 MB/s |
Median of 7 runs after warmup, on Apple M5 Pro, 24 GB RAM, Node 24.3.0. Inputs are generated
by scripts/benchmark.ts rather than checked in, so the sizes above are
exactly what was measured. Reproduce with bun run benchmark.
These are machine-specific and are not asserted in CI β a benchmark that gates
a build only tells you how busy the runner was.
Testing
| Metric | Coverage |
|---|
| Statements | 93.74% |
| Branches | 87.11% |
| Functions | 96.56% |
| Lines | 94.73% |
424 test cases across 29 files, plus an integration suite that runs
in a real VS Code extension host and an end-to-end test that installs the
built .vsix into a clean profile.
Generated from a real run β coverage/coverage-summary.json and
coverage/test-results.json β by scripts/coverage-readme.js; CI fails if
this section drifts. Reproduce with bun run test:coverage, and the case
count is the one vitest prints.
More from the LE family
Sixteen single-purpose tools for the work in front of every model. Each ships
a Rust CLI and an MCP server. One page: letools.dev
Get it out
- String-LE β Extract every string in a codebase, with its position, so a person can read them
- Numbers-LE β Extract every hardcoded number in a codebase, so a person can check them
- Units-LE β Extract every quantity with its unit, normalized, and refuse the ambiguous ones by name
- Dates-LE β Extract every date and timestamp, and the exact instant each one resolves to
- IDs-LE β Extract every UUID, ULID, NanoID, ObjectId and Snowflake, and decode the time inside
- IPs-LE β Extract every IP address, CIDR block and MAC, normalized and classified by scope
- URLs-LE β Extract every URL in a codebase, with its protocol and exact position
- Paths-LE β Extract every file path in a codebase, and say whether it still points at anything
- Colors-LE β Extract every color in a codebase, and say which ones are not in your palette
Check it
- Regex-LE β Find every regex in a codebase, and report which can be driven into catastrophic backtracking
- Versions-LE β Find where one dependency is constrained differently across a repository's manifests
- i18n-LE β Identify the i18n library a project uses, then audit its catalogs by that library's rules
- Scrape-LE β Check whether a page is scrapeable before the scraper is written, and say when it cannot tell
Guard it
- Secrets-LE β Find hardcoded credentials in a codebase, and never print one into the report
- EnvSync-LE β Compare the dotenv files in a tree, and say which keys are missing from which
- Unicode-LE β Find the Unicode that hides meaning β bidi controls, invisibles, homoglyphs, mixed scripts
Each stands on its own: no shared crate, no published core. Where two of them
agree, it is because the same answer was right twice.
Contact β nolindnaidoo.com Β· GitHub Β· LinkedIn
Also by nolindnaidoo
Rust β pixelcoords and pixelactions are one loop: pixelcoords answers
where, pixelactions acts there. Their own tools, their own voice β not
part of the LE family.
License
MIT Β© nolindnaidoo