Lightweight transparent proxy for Keenetic/Netcraze routers, powered by sing-box.
🇺🇸 English | 🇷🇺 На русском
SKeen configures transparent proxying on Keenetic and Netcraze routers using sing-box. It manages firewall rules, service lifecycle and configuration synchronization.
Why sing-box?
sing-box is an open-source universal proxy engine written in Go. It is focused on maximum performance, low resource consumption, and support for the most modern protocols
Comparison: Proxy Engines for Routers & Embedded
| Feature | sing-box | Xray | mihomo |
|---|---|---|---|
| Resource Usage (RAM/CPU) | ✅ Minimal | ❌ High | |
| Protocol Support | ✅ Advanced | ✅ Extensive | |
| Multiplexing | ✅ Superior | ✅ Good | |
| DNS Logic | 🥇 Native (+Fake-IP) | 🥉 Sniffing (+FakeDNS) | 🥈 Fake-IP (+Real) |
| TUN efficiency | ✅ High | ||
| L7 Sniffing (Protocols) | ✅ Leader | ❌ Domain-only | |
| Routing | ✅ Flexible | ✅ (but heavier) | |
| Rule Management | ✅ Rule-sets (bin) | ✅ Rule-providers | |
| Independent Project | ✅ Yes | ❌ (V2Ray fork) | ❌ (Clash fork) |
| Learning Curve | 🔴 High | 🟡 Moderate | 🟢 Low |
Notes:
sing-box excels due to its modularity and clean-slate architecture: its DNS stack enables complex configurations with minimal RAM overhead. In contrast, mihomo (Clash) prioritizes automation at the cost of high resource usage, while Xray is hindered by legacy networking code and heavy .dat geo-files.
Sniffing Differences: sing-box and Xray utilize full DPI (Deep Packet Inspection), which allows them to identify the protocol type (e.g., BitTorrent) based on packet content. In contrast, mihomo is limited to metadata extraction (domains) from TLS/HTTP headers, making protocol-based routing impossible.
The high learning curve of sing-box stems from its strict JSON schema and lack of "magic" defaults. This is a trade-off for granular control and peak performance on low-end hardware.
Web UI?
💡 For easy setup, a sync plugin is available, allowing you to import profiles via GUI.for.SingBox. For more flexible manual configuration, automation, and synchronization, use Sub-Store-Docker on a VPS or Sub-Store-GUI on a PC.
The project intentionally does not include a dedicated management panel. This approach offers several advantages for your router:
- Resource Efficiency: Not having a separate management panel saves RAM and reduces CPU overhead, leaving more resources for traffic routing.
- Integration: Management and monitoring are available through the sing-box API and router tools, without duplicating their functions in a separate panel.
- Security and Stability: Fewer continuously running services and components mean fewer potential points of failure and conflicts within the system.
- Full Control: Directly editing the configuration provides access to sing-box features without the limitations of simplified graphical interfaces. Implementing all these features as buttons requires developers to continually update and promptly maintain the panel.
- No Constant Need: In general, a separate management panel is not required: a correctly configured setup is created for specific tasks and usually does not need regular changes.
- Focus on the Main Task: SKeen is designed for transparent traffic forwarding and routing. For a network tool of this kind, a separate heavy management panel would generally be excessive.
- TProxy, Redirect, Hybrid, Tun and DNS modes
- IPv4 and IPv6 support
- Working sing-box DNS module
- Working sing-box FakeIP
- FakeIP proxying at iptables level
- Configured Web UI via built-in API
- Network settings optimization
- Commands working via router's Web CLI
- Switch between official and third-party sing-box
- Sing-box config sync via HTTP(S) link
- Sub-Store usage examples for synchronization
- Ready-to-use sing-box config templates
- Optional proxying for the router itself
- No access token required for RCI requests
- Entware installed and configured.
- Netfilter Subsystem Kernel Module installed.
curlinstalled viaopkg install curl.- Recommended: at least 256 MB of RAM and an ARM processor to unlock full potential.
Make sure that Entware is installed. Otherwise, find the instructions for your model in the Support Center → User Guide → Management → OPKG → Installing the Entware repository on a USB drive / Installing OPKG Entware on internal router memory.
Run from Entware via SSH:
curl -Ls https://github.com/jinndi/SKeen/releases/latest/download/skeen --resolve release-assets.githubusercontent.com:443:185.199.108.133 | shRussian-localized version: See README-RU.md
Note
You will be prompted to install sing-box from the official repository (either the stable or beta version). You can also skip the installation to configure a custom binary file later in skeen.json.
Configure the following:
- SKeen in
/opt/etc/skeen/skeen.json. - sing-box in
/opt/etc/skeen/config.json. - The web dashboard at
http://192.168.1.1:9999. By default, it is available at the router's IP address (typically192.168.1.1).
Important:
The /opt/etc/skeen directory is preserved when the program is uninstalled and is not overwritten during reinstallation if it already exists. Delete it manually if necessary.
Manage SKeen using the skeen command.
File and directory structure after successful installation:
/opt/
├── bin/
│ ├── skeen # Main SKeen management script
│ └── skeen-box # sing-box binary (if installation selected)
├── etc/
│ ├── init.d/
│ │ └── S99SKeen # System startup / autostart script
│ ├── ndm/netfilter.d/
│ │ └── skeen_firewall.sh # Firewall rules (generated on startup)
│ └── skeen/
│ ├── skeen.json # SKeen configuration
│ └── config.json # sing-box configuration
└── tmp/ # Temporary download files
/tmp/ (RAM Disk) - synced into memory:
├── skeen.sh # Script copy - updated after start/reboot
├── skeen.json # Config cache - synced on source changes
├── skeen_singbox_version # sing-box version cache - updated on binary change
└── run/
└── skeen.pid # PID file of the sing-box process
The following domains are pre-configured in the base config.json template for accessing the panels from the router's local network:
| Dashboard URL | Used API | Panel Connection Address | Brief Description |
|---|---|---|---|
| sing-box-dashboard.sagernet.org (in Chrome) HTTP version (others) |
Native sing-box API (9999) |
http://192.168.1.1:9999 |
Built-in sing-box web dashboard (files are stored locally on the router). |
| sdash.u1.pw (in Chrome) HTTP version (others) |
Native sing-box API (9999) |
http://192.168.1.1:9999 |
Very lightweight web interface for sing-box management. |
| board.zash.run.place (in Chrome) HTTP version (others) |
Clash API (9090) |
http://192.168.1.1:9090 |
Remote Zashboard frontend for managing proxy connections. |
| d.metacubex.one / metacubexd.pages.dev (Chrome only) | Clash API (9090) |
http://192.168.1.1:9090 |
Alternative MetacubexD (Yacd-meta) web interface for Clash API. |
Example Usage from SSH: start the daemon skeen start
When using the router’s Web CLI, add exec before the command. For example: exec skeen reload
The output in the Web CLI is limited to 8 lines and a certain execution time, but this does not affect the correct execution of commands.
skeen without parameters launches the management menu from SSH, use skeen help for help
| Command | Description | Web CLI |
|---|---|---|
start |
Start service | ✓ |
stop |
Stop service | ✓ |
restart |
Full restart | ✓ |
reload |
Reload sing-box only | ✓ |
kill |
Force stop | ✓ |
status |
Show status | ✓ |
version |
Show version | ✓ |
help |
Help about any command | - |
iface |
Show network interface table | - |
update |
Check and install updates | - |
test |
Test firewall rules | ✓ |
deps |
Check dependencies | ✓ |
check |
Check configuration | ✓ |
format |
Format sing-box configuration | ✓ |
api |
sing-box API management commands | - |
backup |
Create archive of /opt/etc/skeen |
✓ |
backups |
List created archives in /opt |
✓ |
restore¹ |
Restore /opt/etc/skeen from archive in /opt |
✓ |
reset |
Reset /opt/etc/skeen to default |
- |
clean² |
Clear sing-box cache file | ✓ |
sync³ |
Synchronize sing-box configuration | ✓ |
headers |
Generate fake client headers for subscriptions | - |
1 - archive name can be passed as the second parameter with a .tar extension to immediately start the backup restore process
2 - clears the cache file. This is required when using the experimental.cache_file feature in sing-box, for example, to reset the cache of loaded rule_set and DNS query history.
3 - accepts the sing-box JSON configuration URL as the second parameter (HTTP or HTTPS); optional if the address is set in singbox.config.url
OpkgTun manager (KeeneticOS v5+, only from SSH)
| Command | Description |
|---|---|
skeen tun create <ipv4> <name> |
Create interface with IP address and name |
skeen tun delete <name> |
Delete interface by name |
skeen tun list |
List all OpkgTun interfaces |
The full configuration reference is available in docs/CONFIGURATION.md.
Sync and GUI
- Sub-Store Desktop — desktop subscription manager.
- Sub-Store Android — Android app for managing subscriptions.
- Sub-Store Docker — Docker deployment for VPS and servers.
- GUI.for.SingBox sync plugin — plugin for importing profiles into SKeen.
Rulesets
- Karing ruleset — rule sets for sing-box.
- Custom sing-box rulesets — custom rule sets.
Documentation and references
- core-tutorial.argsment.com — sing-box reference guide.
- sing-box-lx core (XHTTP) — alternative XHTTP-capable core.
