Install
$ agentstack add skill-vanducng-skills-py2go ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
py2go
End-to-end Python → Go migration. Discover the source, lock the design, scaffold the Go module, translate file-by-file with TDD, validate behavioral parity against real data, cut over, then sweep dead code.
The skill is opinionated. It enforces idiomatic Go output over Python-shaped Go, rejects dead toolchains (Grumpy/py2go transpilers), defaults to sqlc over GORM, defaults to pgx over lib/pq, defaults to Gin for HTTP, prefers stdlib slog over zap/zerolog, and treats real-data parity validation as non-optional.
When to load which reference
| Task | Open | |---|---| | Decide which Python pattern maps to which Go idiom | [references/translation-rules.md](references/translation-rules.md) | | Pick the right Go stack per project type | (playbooks — extend as needed) | | Configure strangler-fig gateway / traffic shadow | (extend as needed) | | Drive from an existing OpenAPI/proto spec | (extend as needed) |
The 7 phases
discover → design → scaffold → translate → validate → cutover → cleanup
- Discover — two-pass: 7 discovery prompts individually → synthesize to
notes/ - Design — emit
CLAUDE.md(translation rules) +MIGRATION.md(ordered file map + checkboxes) - Scaffold —
go mod init, layout, lint (golangci-lint), CI, Makefile, smoke target - Translate — per-file loop: Python source → Go test first → Go impl →
go build && vet && test -race && lint→ commit - Validate — golden-file parity on real production data + integration tests + dead-code sweep
- Cutover — hard cutover (default) or strangler-fig (
--strangler) - Cleanup — orphan sweep, dependency audit, retro
Project-type playbooks (auto-detected in discover)
| Type | Detected from | Go stack | |---|---|---| | CLI | Click/Typer imports, entry_points consolescripts | Cobra + Viper + lipgloss | | TUI | Textual / Rich.live / prompttoolkit | Bubble Tea + Bubbles + Lipgloss | | HTTP | FastAPI/Flask/Django/Starlette | Gin (default) / chi / Echo / Fiber | | Pipeline | pandas/polars/Airflow/Prefect/Dagster | streaming []T + channels; qframe; STOP if NumPy/SciPy heavy | | Worker | Celery/RQ/Dramatiq/Arq/Taskiq | asynq (Redis) or river (Postgres) | | Library | __init__.py exports | pkg/ layout with forced public-API decision |
Hard guardrails (skill enforces)
- No 1:1 syntax port — Go function signatures must not mirror Python verbatim across >50% of lines.
- TDD-or-bust under
--strict-tdd— Go test mtime must precede Go impl mtime per commit. - No
lib/pq— usepgx/v5. lib/pq is in maintenance mode. - No
golang/mock— usego.uber.org/mock(Google archived original). - No GORM by default —
sqlcis default; GORM requires explicit--orm=gormflag. - No
panicfor business errors — return errors. - No blind
internal/— design phase must produce an explicit public-API decision. - No synthetic-only validation — validate phase refuses to mark complete without a real-data fixture path.
- NumPy/SciPy refusal — if discovery detects them load-bearing, STOP with gRPC-wrap recommendation instead.
Cross-refs into the rest of the skill ecosystem
- [gostack](../gostack/SKILL.md) — Sam Berthe's Go libraries (lo, oops, do, mo, slog, hot, ro). See
references/translation-rules.mdfor where each library is the right answer. vd:cook— once a plan + MIGRATION.md is in place, drive execution phase-by-phasevd:debug— for the on-call storyoops/slogenables in the migrated servicevd:ship— for the final cutover commit + PR
Versions snapshot (verified 2026-05-23)
Locked defaults — change requires explicit flag.
| Concern | Pinned default | Cite | |---|---|---| | HTTP framework | gin v1.x | Go Survey 2025: 48% adoption | | Postgres driver | pgx/v5 | lib/pq in maintenance | | DB access | sqlc | 2× faster than GORM on 15k-row reads | | Migrations | golang-migrate | Multi-DB, CI-friendly | | Config | viper | Cobra ecosystem alignment | | Logger | log/slog (stdlib) | Survey 2025 default for new code | | Validation | go-playground/validator | Default with Gin | | Mocking | go.uber.org/mock | Google archived golang/mock | | OpenAPI codegen | oapi-codegen | Supports Gin/chi/Fiber | | Queue | asynq (Redis) or river (Postgres) | Celery-shaped or PG-native | | Cache | ristretto or gostack@hot | See [gostack/hot](../gostack/references/hot.md) | | Auth | golang-jwt/v5 + argon2 | OWASP 2025 recommendation | | Observability | OpenTelemetry + Prometheus | Industry standard | | Build/release | goreleaser + ko | Container without Dockerfile |
Adding a new project-type playbook
- Detect signal in discover phase (imports, file conventions)
- Drop
references/playbook-.mdwith the canonical Go stack for that shape - Add a row to the "Project-type playbooks" table above
- Update translation rules where the playbook diverges from defaults
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: vanducng
- Source: vanducng/skills
- License: MIT
- Homepage: https://skills.vanducng.dev
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.