The browser replaces hand-edited WARP configuration files
Usque Custom Pro turns a fiddly Cloudflare WARP MASQUE setup into a web form. It registers a device, generates a P-256 key in the browser, enrolls the public key, and lets you download the resulting native configuration. That file can then feed generators for Clash or Mihomo, Shadowrocket, sing-box, and a local VLESS bridge. The project also creates groups for specific services and candidate endpoints for connection testing.
The documentation is Chinese throughout its roughly 1,500 lines, and there is no English README in the 24-file tree. That is a practical limit because the tool handles private keys, tokens, routing rules, and client-specific output. Machine translation may explain a button, but a production operator needs to understand the warning that entry endpoints and final WARP exit addresses are different things.
The 18-second install prepares Wrangler, not a finished route
Our commit 8719fa0 checkout occupied 0.3 MB and contained about 4,406 lines of source. The npm project lives in workers/. Installing 45 packages took 18 seconds and expanded the environment to 220 MB. The package has commands for Wrangler development, deployment, and a JavaScript syntax check, while the measured harness found no conventional build target.
Deployment offers 2 paths. Cloudflare Pages is the recommended route: point the project root at pages/, leave the build command empty, and publish the directory as-is. The Workers route runs from workers/, asks Wrangler to authenticate your Cloudflare account, and deploys the static assets plus API worker. A health endpoint confirms the page and worker route are reachable after publication.
What happened when we ran it
Our sandbox installed 45 npm packages in 18 seconds, using 220 MB after installation. Npm audit reported 0 known vulnerabilities across the measured dependency tree. The run used Node 22 in a fresh unprivileged Debian container with 3 CPUs, 8 GB of RAM, and no secrets. The repository itself held 24 files and about 4,406 source lines.
There was no build script or build target, so the build step was skipped. The same was true for tests: no test script or target was available. Our scan found 0 CI workflow files, no Dockerfile, and no tests directory. We did not deploy to Cloudflare or register a WARP device, so the clean dependency audit says nothing about generated routing correctness or live account registration.
The downloaded file carries the account secrets
The native configuration can include the MASQUE private key, access token, license field, device ID, and assigned addresses. The README says the key is generated in the browser and that the application does not persist credentials in Cloudflare KV, D1, R2, localStorage, or sessionStorage. That reduces server-side storage, though it moves the lasting custody problem to every downloaded usque-config.json.
The project tells users to exclude that file, Wrangler state, environment files, logs, and egress reports from Git. That advice matters because the workflow encourages repeated download and import. Open issue 1 asks for a subscription URL precisely because changing settings currently means generating another file and importing it again. Adding server-side subscriptions would change the current no-database security model and require a fresh design review.
Four open issues leave routing compatibility unsettled
The repository was created on September 4, 2026 and last pushed on September 9. GitHub showed 1,422 stars, 2,305 forks, 4 open issues, and 0 open pull requests. No GitHub release was published. The short activity window and high fork count show interest, but they provide little evidence about maintenance after Cloudflare or a client changes behavior.
One open report says Chinese websites became unreachable when the generated configuration ran in OpenClash. Another includes rule-provider failures and MASQUE connection closures on an Android client. User reports do not establish a universal defect, yet both touch the product's central promise: generating working client configurations. A router owner should validate domestic routes, DNS behavior, and each required service before replacing an existing profile.
Missing license terms stop serious reuse
GitHub's API reports no license, and the commit tree has no LICENSE file. Public source code is still governed by copyright when no permission is granted. That leaves companies without clear rights to copy, modify, redistribute, or deploy a fork. The omission matters more here because the README explicitly tells users to upload the project to their own GitHub account for Cloudflare Pages deployment.
Version labels also need cleanup. The README title says v6.17, its introduction and directory section say v6.7, and workers/package.json declares 6.7.0. With 0 published releases, there is no tag that resolves which label marks the reviewed state. Our 18-second install and clean audit make experimentation easy, but explicit licensing and a repeatable test path should come before organizational adoption.

