
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
dsh-pathlink
Advanced tools
Ctrl+click file paths and links in DeepSeek Harness chat (paths open their folder), and drop or paste any file to get its path inserted in the composer.
Ctrl+click file paths and links in DeepSeek Harness chat; drop a file to get its path.
Recognizes file paths and URLs in rendered chat messages (assistant replies, user bubbles, code blocks, tool cards), marks them with a subtle dotted underline, and opens them with Ctrl+click (⌘ on macOS):
explorer /select, macOS open -R, Linux
xdg-open on the parent directory). A path that names a directory opens the
directory itself.Drop or paste any file → its path lands in the composer (images keep the built-in attachment flow):
D:\proj\src\a.ts);%TEMP%\dsh-drops\ and that path is inserted, with a notice
saying so;Plain clicks stay inert, so text selection and copy are never disturbed. When a path does not exist, a small toast explains why instead of failing silently.


① Hovering a path shows the Ctrl+click hint — Ctrl+click opens the containing folder with the file selected · ② The recognized path in a real conversation (dotted underline).
dsh plugin --profile web add dsh-pathlink
or via GitHub:
dsh plugin --profile web add github:penguin-oo/dsh-pathlink
Restart the web GUI afterwards. Requires the web profile (a browser is the only surface that can receive the click).
| Key | Default | Meaning |
|---|---|---|
maxPathChars | 1024 | Longest accepted path text, in characters |
dropRoots | [] | Extra search roots for a dropped file (tried first) |
dropMaxDepth | 6 | Recursion cap for one locate scan |
dropBudgetMs | 2500 | Time budget for one locate scan |
dropLimit | 10 | Matches collected per root |
dropDir | '' | Where an unlocatable drop is copied; '' = %TEMP%\dsh-drops |
Search order: dropRoots → the harness's own workspace list (harvested) →
process cwd / Desktop / Downloads / Documents. Debug endpoint:
GET /pathlink/drop/state.
dsh.client, platform web): a MutationObserver-driven
scanner watches the rendered conversation containers (data-chat-flow /
data-conversation-scroll), recognizes paths and URLs in text nodes, wraps
matches in inert inline spans, and handles one delegated capture-phase click
listener. The official chatFileMentions seam is deliberately not used so
the plugin never conflicts with the built-in deliverables provider and
covers every surface uniformly.pathlink Remote service): one read-only open method that
resolves relative paths against the addressed session's working directory,
verifies existence, and launches the platform file manager. No durable
state; it never creates or resumes an Agent or Session.npm install
npm run build # bundle src/client → lib/client.js
npm run smoke # Remote markers + Typert manifest validation
node scripts/e2e-synthetic.mjs # browser E2E against http://127.0.0.1:3738
docs/demo.html is built with node scripts/build-demo.mjs (reuses the
production recognizer) and screenshotted by node scripts/e2e-screenshot.mjs.
MIT
Built for the DeepSeek Harness plugin ecosystem — thanks to the community on LINUX DO for feedback and testing.
FAQs
Ctrl+click file paths and links in DeepSeek Harness chat (paths open their folder), and drop or paste any file to get its path inserted in the composer.
The npm package dsh-pathlink receives a total of 109 weekly downloads. As such, dsh-pathlink popularity was classified as not popular.
We found that dsh-pathlink demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.