跳到主要内容
知仓学习社ZHICANG

douban-skill

>

读凭据联网写文件读文件严重 0 · 高危 6daymade/claude-code-skills

它会碰到什么

扫了多少5 个文本文件,32 KB
它会碰到什么读凭据联网写文件读文件
命中总数22 处
命中统计严重 0 · 高 6 · 中 10 · 低 6
逐条看命中(6 条严重或高危)
  • scripts/douban-frodo-export.py:86cred-envread
    return os.path.join(os.environ.get('USERPROFILE', os.path.expanduser('~')), 'Downloads')
  • scripts/douban-frodo-export.py:93cred-envread
    base = os.environ.get('DOUBAN_OUTPUT_DIR')
  • scripts/douban-frodo-export.py:267cred-envread
    user_id = os.environ.get('DOUBAN_USER', '').strip()
  • scripts/douban-rss-sync.mjs:23cred-envread
    let DOUBAN_USER = process.env.DOUBAN_USER;
  • scripts/douban-rss-sync.mjs:32cred-envread
    return path.join(process.env.USERPROFILE || os.homedir(), 'Downloads');
  • scripts/douban-rss-sync.mjs:37cred-envread
    const BASE_DIR = process.env.DOUBAN_OUTPUT_DIR || path.join(getDownloadDir(), 'douban-sync');

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Douban Collection Export

Export Douban user collections (books, movies, music, games) to CSV files.

Douban has no official data export; the official API shut down in 2018.

What This Skill Can Do

  • Full export of all book/movie/music/game collections via Frodo API
  • RSS incremental sync for daily updates (last ~10 items)
  • CSV output with UTF-8 BOM (Excel-compatible), cross-platform (macOS/Windows/Linux)
  • No login, no cookies, no browser required
  • Pre-flight user ID validation (fail fast on wrong ID)

What This Skill Cannot Do

  • Cannot export reviews (长评), notes (读书笔记), or broadcasts (广播)
  • Cannot filter by single category in one run (exports all 4 types together)
  • Cannot access private profiles (returns 0 items silently)

Why Frodo API (Do NOT Use Web Scraping)

Douban uses PoW (Proof of Work) challenges on web pages, blocking all HTTP scraping.

We tested 7 approaches — only the Frodo API works. Do NOT attempt web scraping,

browser_cookie3+requests, curl with cookies, or Jina Reader.

See [references/troubleshooting.md](references/troubleshooting.md) for the complete

failure log of all 7 tested approaches and why each failed.

Security & Privacy

The API key and HMAC secret in the script are Douban's public mobile app credentials,

extracted from the APK. They are shared by all Douban app users and do not identify you.

No personal credentials are used or stored. Data is fetched only from frodo.douban.com.

Full Export (Primary Method)

DOUBAN_USER=<user_id> python3 scripts/douban-frodo-export.py

Finding the user ID: Profile URL douban.com/people/<ID>/ — the ID is after /people/.

If the user provides a full URL, the script auto-extracts the ID.

Environment variables:

  • DOUBAN_USER (required): Douban user ID (alphanumeric or numeric, or full profile URL)
  • DOUBAN_OUTPUT_DIR (optional): Override output directory

Default output (auto-detected per platform):

  • macOS: ~/Downloads/douban-sync/<user_id>/
  • Windows: %USERPROFILE%\Downloads\douban-sync\<user_id>\
  • Linux: ~/Downloads/douban-sync/<user_id>/

Dependencies: Python 3.6+ standard library only (works with python3 or uv run).

Example console output:

Douban Export for user: your_douban_id
Output directory: /Users/you/Downloads/douban-sync/your_douban_id

=== 读过 (book) ===
  Total: 639
  Fetched 0-50 (50/639)
  Fetched 50-100 (100/639)
  ...
  Fetched 597-639 (639/639)
  Collected: 639

=== 在读 (book) ===
  Total: 75
  ...

--- Writing CSV files ---
  书.csv: 996 rows
  影视.csv: 238 rows
  音乐.csv: 0 rows
  游戏.csv: 0 rows

Done! 1234 total items exported to /Users/you/Downloads/douban-sync/your_douban_id

RSS Incremental Sync (Complementary)

DOUBAN_USER=<user_id> node scripts/douban-rss-sync.mjs

RSS returns only the latest ~10 items (no pagination). Use Full Export first, then RSS for daily updates.

Output Format

Four CSV files per user:

Downloads/douban-sync/<user_id>/
├── 书.csv      (读过 + 在读 + 想读)
├── 影视.csv    (看过 + 在看 + 想看)
├── 音乐.csv    (听过 + 在听 + 想听)
└── 游戏.csv    (玩过 + 在玩 + 想玩)

Columns: title, url, date, rating, status, comment

  • rating: ★ to ★★★★★ (empty if unrated)
  • date: YYYY-MM-DD (when the user marked it)
  • Safe to run multiple times (overwrites with fresh data)
  • Row counts may be slightly below Douban's displayed count due to delisted items

Workflow

  1. Ask for Douban user ID (from profile URL, or accept full URL)
  2. Run: DOUBAN_USER=<id> python3 scripts/douban-frodo-export.py
  3. Verify: row counts in console output should match, check with wc -l <output_dir>/*.csv
  4. (Optional) Set up RSS sync for daily incremental updates

Troubleshooting

See [references/troubleshooting.md](references/troubleshooting.md) for:

  • Frodo API auth details (HMAC-SHA1 signature computation)
  • Common errors (code 996 signature error, rate limits, pagination quirks)
  • Complete failure log of all 7 tested approaches with root causes
  • Alternative approaches (豆伴 extension, Tampermonkey script, browser console)
  • API endpoint reference with response format

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。