Agent skill

E2E Testing

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when writing or stabilizing Playwright tests that drive a real browser through multi-step journeys — durable locators, web-first assertions, storageState auth, trace/retries…

MITAuto-check passedTesting & QA

Install E2E Testing

skills CLI
$ npx skills add ericrisco/rsc-harness --skill e2e-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness e2e-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/e2e-testing .claude/skills/e2e-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
e2e-testing
GitHub stars
156
Token cost
~3.2k tokens
SKILL.md length
1,238 words
Files
6 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when writing or stabilizing Playwright tests that drive a real browser through multi-step journeys — durable locators, web-first assertions, storageState auth, trace/retries…

  • Works in 5 steps: getByRole('button', { name: 'Buy' }) —… → getByLabel('Email') /… → getByText('Order confirmed') — visible… → …
  • Stabilizing Playwright tests that drive a real browser through multi-step journeys — durable locators
  • SKILL.md covers Is this even an e2e test?, Locators: the priority ladder, Assertions: web-first only and Auto-wait and the no-sleep rule, plus 7 more sections
  • Runs Shell scripts from its folder; calls npx

What it does

E2E Testing is an agent skill from ericrisco/rsc-harness. Use when writing or stabilizing Playwright tests that drive a real browser through multi-step journeys — durable locators, web-first assertions, storageState auth, trace/retries, and flakes that only bite in CI. NOT in-process component tests (that is testing-web), NOT WCAG auditing (that is accessibility), NOT the pre-merge gate (that is verify).

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/config-and-ci.md`).

It sits in Testing & QA, covering End-to-end testing, Accessibility and Browser testing. It works with Playwright. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Stabilizing Playwright tests that drive a real browser through multi-step journeys — durable locators
  • Web-first assertions
  • StorageState auth
  • Flakes that only bite in CI

Example prompts

  • “/e2e-testing”

Requirements

  • Node.js
  • A Bash shell

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. getByRole('button', { name: 'Buy' }) — role + accessible name. Default choice; doubles as an a11y signal.
  2. getByLabel('Email') / getByPlaceholder(...) — form fields.
  3. getByText('Order confirmed') — visible copy that uniquely identifies content.
  4. getByTestId('cart-total') — when nothing user-facing is stable; requires a deliberate data-testid.
  5. CSS as a last resort, scoped and shallow.

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

E2E Testing loads about 3.2k tokens when it runs, and up to ~5.9k if it reads all its reference files. Until then it costs about 90 tokens; SKILL.md has 1,238 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,238 words, ~3,153 tokens.

Download SKILL.mdSave it as .claude/skills/e2e-testing/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
e2e-testing
description
Use when writing or stabilizing Playwright tests that drive a real browser through multi-step journeys — durable locators, web-first assertions, storageState auth, trace/retries, and flakes that only bite in CI. NOT in-process component tests (that is testing-web), NOT WCAG auditing (that is accessibility), NOT the pre-merge gate (that is verify).
tags
playwright, e2e, browser-testing, flakiness, ci
recommends
testing-web, accessibility, performance, github-actions, debug
origin
risco

e2e-testing — drive a real browser, keep it deterministic

You write Playwright tests that walk a real browser through real user journeys — log in, fill a form, check out, navigate across pages — and you keep those tests deterministic enough to gate a merge. The whole game is one tension: e2e tests catch integration bugs nothing else can, and they are the slowest, flakiest layer you own. Every rule below exists to buy back determinism.

Pin @playwright/test and provision browsers with npx playwright install --with-deps. Current line is Playwright v1.60.x (v1.60.0 shipped 2026-05-11). The _react / _vue selector engines and the :light Shadow-DOM suffix were removed in v1.58.0 — at any version you should be pinning they are long gone, so do not reach for them.

Is this even an e2e test?

E2e is the most expensive layer. Spend it only on journeys that cross pages or services. Route the rest out.

The goal is…LayerWhy
A multi-step journey across pages/auth/services in a real browsere2e (here)Only a real browser proves the pieces integrate.
One component or pure function, rendered in-process (Vitest/Jest, Testing Library)../testing-web/SKILL.mdA browser round-trip to test render logic is slow and flaky for no gain.
"Is this page accessible?" — WCAG/ARIA as the deliverable../accessibility/SKILL.mdE2e may call axe inside a test, but auditing a11y is its own skill.
"Is this page fast?" — LCP/CWV budgets../performance/SKILL.mdPerf budgets are a different signal than journey correctness.
The runner matrix, caching, the pipeline itself../github-actions/SKILL.mdE2e contributes a job; owning the pipeline is theirs.
"Is the change done?" — run the gate, collect evidence, then merge../verify/SKILL.mdRunning an existing suite as a pre-merge gate is not authoring or stabilizing one.

Rule: if you can prove it without launching a browser, you should. Push logic down to testing-web.

Locators: the priority ladder

Pick the highest rung that uniquely identifies the element. Higher rungs track what the user perceives, so they survive markup churn.

  1. getByRole('button', { name: 'Buy' }) — role + accessible name. Default choice; doubles as an a11y signal.
  2. getByLabel('Email') / getByPlaceholder(...) — form fields.
  3. getByText('Order confirmed') — visible copy that uniquely identifies content.
  4. getByTestId('cart-total') — when nothing user-facing is stable; requires a deliberate data-testid.
  5. CSS as a last resort, scoped and shallow.

Never XPath, never nth-child chains, never the removed _react/_vue/:light engines.

ts
// Bad — couples the test to DOM structure; one wrapper div breaks it.
await page.locator('div.card > button:nth-child(2)').click();

// Good — finds the button the way the user reads it.
await page.getByRole('button', { name: 'Buy' }).click();

Strict mode. A locator that matches two nodes throws — that is the framework catching an ambiguous selector for you. Tighten the locator (getByRole(...).and(...), scope with page.getByRole('listitem').filter({ hasText: 'Pro' })). Reaching for .first() to silence the error hides the ambiguity and is the next flake.

Assertions: web-first only

ts
// Bad — reads the DOM once, before the async update lands; races the render.
expect(await page.locator('#status').textContent()).toBe('Submitted');

// Good — re-polls the element until it says 'Submitted' or the timeout fires.
await expect(page.getByTestId('status')).toHaveText('Submitted');

expect(locator) assertions (toBeVisible, toHaveText, toHaveURL, toHaveCount) retry until the condition holds. A read-once value (await locator.textContent() then compare) captures a single frame and loses every race against a re-render. If you find expect(await in a test, it is a bug.

Auto-wait and the no-sleep rule

Locator actions (click, fill, check) already auto-wait: they block until the element is visible, stable, enabled, and receiving events. So waitForTimeout(2000) is never the right wait — it is either too short (flake) or too long (slow), and it waits for wall-clock time instead of the thing you actually care about.

Instead of guessing with a sleepWait on the real signal
"give the button time to appear"await expect(locator).toBeVisible()
"wait for navigation"await page.waitForURL('**/checkout')
"wait for the XHR/fetch"const r = page.waitForResponse('**/api/order'); …action…; await r;
"wait for the list to fill"await expect(page.getByRole('row')).toHaveCount(5)

The ordering trap: subscribe to a response (or register a page.route mock) before the action that triggers it, or you miss the event.

ts
// Bad — handler registered after goto; the initial request already fired unmocked.
await page.goto('/orders');
await page.route('**/api/orders', route => route.fulfill({ json: [] }));

// Good — mock in place before navigation, so the first request is intercepted.
await page.route('**/api/orders', route => route.fulfill({ json: [] }));
await page.goto('/orders');

Fixtures and page objects

Fixtures give every test a fresh, isolated setup and kill copy-pasted boilerplate. Extend the base test with your own; the code before use(value) is setup, after it is teardown.

ts
import { test as base } from '@playwright/test';
import { CheckoutPage } from './pages/checkout';

type Fixtures = { checkout: CheckoutPage };

export const test = base.extend<Fixtures>({
  checkout: async ({ page }, use) => {
    const checkout = new CheckoutPage(page); // setup: depends on the built-in `page`
    await use(checkout);                      // hand it to the test
    // teardown after the test goes here, if any
  },
});

Option fixtures (['default', { option: true }]) let a project or test.use() flip behavior without new fixtures. Keep page objects thin — locators and intent-named actions (checkout.placeOrder()), no assertions buried inside them. Full page-object recipe lives in references/config-and-ci.md.

Auth and storageState

Logging in through the UI on every test is slow and a flake surface. Log in once in a setup project, save the authenticated session to JSON, and load it via storageState in the projects that depend on it.

  • A setup project runs the login spec and writes playwright/.auth/<role>.json.
  • Real test projects declare dependencies: ['setup'] and use: { storageState: '…/<role>.json' }.
  • One file per role (admin, member, anon) — never share one mutated session across roles.
  • Regenerate every CI run; gitignore the .auth/ dir. Committed session state leaks secrets and goes stale.

The full multi-role setup-project wiring is in references/config-and-ci.md.

Show full SKILL.md (485 more words)Show less

playwright.config.ts (condensed)

ts
import { defineConfig, devices } from '@playwright/test';

export default defineConfig({
  testDir: './e2e',
  fullyParallel: true,
  forbidOnly: !!process.env.CI,        // a stray test.only fails CI instead of skipping the suite
  retries: process.env.CI ? 2 : 0,     // retry only in CI; locally a flake should hurt
  workers: process.env.CI ? 1 : undefined,
  reporter: process.env.CI ? [['github'], ['html']] : 'list',
  use: {
    baseURL: process.env.BASE_URL ?? 'http://localhost:3000',
    trace: 'on-first-retry',           // full trace captured the first time a test retries
  },
  projects: [
    { name: 'setup', testMatch: /.*\.setup\.ts/ },
    { name: 'chromium', use: { ...devices['Desktop Chrome'] }, dependencies: ['setup'] },
    { name: 'webkit',   use: { ...devices['Desktop Safari'] }, dependencies: ['setup'] },
  ],
  webServer: {
    command: 'npm run start',
    url: 'http://localhost:3000',
    reuseExistingServer: !process.env.CI,
  },
});

Open a captured trace with npx playwright show-trace. The full annotated config (per-role storageState, firefox, blob reporter for sharding) is in references/config-and-ci.md.

CI (GitHub Actions)

The shape: install browsers with OS deps, run, shard when one box can't finish inside the ~5–10 min budget, upload the trace and HTML report as artifacts.

yaml
- run: npx playwright install --with-deps
- run: npx playwright test --shard=${{ matrix.shard }}/4
- uses: actions/upload-artifact@v4
  if: ${{ !cancelled() }}
  with: { name: report-${{ matrix.shard }}, path: playwright-report/, retention-days: 7 }

Scale: bump workers to use a single machine; add --shard=i/N across machines only once a single box overruns the budget. Sharded runs emit blob reports you merge with npx playwright merge-reports. Full workflow (matrix, blob report, merge job) is in references/config-and-ci.md.

Flakiness playbook

A 3% flake rate on a 40-minute pipeline burns roughly an engineer-day a week on reruns, so treat flakes as bugs with named causes. Open the trace first (show-trace) — it replays the exact failing run with DOM, network, and console; guessing from a one-line CI log is how flakes survive.

Symptom in CICauseFix
Assertion races a re-renderRead-once value, not web-firstawait expect(locator).toHaveText(...)
Mock/intercept never firespage.route registered after gotoRegister the route before the navigation
Test hangs / times out in an SPAnetworkidle never settles (polling, websockets)Wait on a locator/URL, not networkidle
waitForResponse misses the callSubscribed after the action firedconst r = page.waitForResponse(...) before the action
"strict mode: resolved to 2 elements"Ambiguous locatorTighten with role+name/filter, not .first()
Passes alone, fails in the suitestorageState leak / shared mutable statePer-role state file; fresh context per test
Wrong fixture/state in one filetest.use() scope confusionScope test.use to the right describe block
Green headed, red headless (or vice-versa)Viewport/animation/timing driftPin viewport; reduce motion; debug in the failing mode

Per-pattern reproduction and corrected code is in references/flakiness-playbook.md.

Anti-patterns

Anti-patternWhy it bitesDo instead
await page.waitForTimeout(2000)Couples the test to wall-clock; too short flakes, too long dragsWait on locator/URL/response
XPath or :nth-child locatorsBreaks on any markup refactor the user never seesgetByRole/getByTestId ladder
page.$(...) / page.$$(...) element handlesNo auto-wait, no retry — pre-locator APIpage.locator(...) / getBy*
expect(await locator.textContent()).toBe(...)Reads one frame; races the async updateawait expect(locator).toHaveText(...)
Committing storageState JSONLeaks session secrets, goes stale, false greenGitignore .auth/; regenerate per run
trace: 'on' alwaysHeavy artifacts, slows every runtrace: 'on-first-retry'
Tests that depend on run orderOne reorder cascades failuresEach test self-contained; fresh context
Driving pure logic through the browserSlow + flaky for a unit-level checkPush it to ../testing-web/SKILL.md
.first() to silence strict modeHides ambiguity → the next flakeMake the locator unique

When a flake resists the table, hand the trace to ../debug/SKILL.md — reproduce as a rate (k/N runs), isolate one variable, fix the cause, not the symptom.

Verify

Run scripts/verify.sh [dir] over the test/config files you emit. It is a read-only static lint (no browser, no network) that fails on the skill's own banlist: waitForTimeout(, XPath/// locators, page.$(/page.$$( handles, expect(await read-once assertions, and any playwright.config.* missing both trace and retries. Clean or empty target exits 0.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/e2e-testing of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/config-and-ci.md
  • references/flakiness-playbook.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

E2E Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

E2E Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
E2E Testing this skillericrisco/rsc-harness156—~3.2kAutomated safety check: PassMIT
React Testingaffaan-m/ECC274k1 repos~3.3kAutomated safety check: PassMIT
Playwright Testingchongdashu/vibejam-starter-pack149—~2.1kAutomated safety check: PassNone
Playwright Testingchongdashu/vibejam-starter-pack149—~2.2kAutomated safety check: PassNone
Agentic Browser Testingpetrkindlmann/qa-skills163—~4.5kAutomated safety check: PassMIT
Web Testing with Playwright and Vitestwithkynam/vibecode-pro-max-kit1.1k—~892Automated safety check: PassApache-2.0

Similar skills

  • React Testing

    affaan-m/ECC

    React component testing with React Testing Library, Vitest/Jest, MSW for network mocking, accessibility assertions with axe, and the decision boundary between component tests and Playwright/Cypress…

    274k GitHub starsUsed in 1 repo~3.3k tokens
    Testing & QAAuto-check passed
  • Playwright Testing

    chongdashu/vibejam-starter-pack

    Plan, implement, and debug frontend tests: unit/integration/E2E/visual/a11y.

    149 GitHub stars~2.1k tokensUpdated 5 mo ago
    Testing & QAAuto-check passed
  • Playwright Testing

    chongdashu/vibejam-starter-pack

    Plan, implement, and debug frontend tests: unit/integration/E2E/visual/a11y.

    149 GitHub stars~2.2k tokensUpdated 5 mo ago
    Testing & QAAuto-check passed
  • Agentic Browser Testing

    petrkindlmann/qa-skills

    Goal-driven E2E testing where a browser agent (Playwright MCP / computer-use) reads a natural-language goal and explores the app via the accessibility tree to assert outcomes — no pre-written script.

    163 GitHub stars~4.5k tokensUpdated 3 mo ago
    Testing & QAAuto-check passed
  • Web Testing with Playwright and Vitest

    withkynam/vibecode-pro-max-kit

    Covers web testing from unit to E2E, load, visual, accessibility and security checks, with Playwright, Vitest and k6 guides plus a Playwright setup script.

    1.1k GitHub stars~892 tokensUpdated 3 mo ago
    Testing & QAAuto-check passed
  • Lit Webview Testing

    forcedotcom/salesforcedx-vscode

    Write or review browser component tests for Lit webviews and VSCode Elements.

    1k GitHub stars~653 tokensUpdated today
    Testing & QAAuto-check passed

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Works with

Questions about E2E Testing

What does E2E Testing do?

A skill your agent uses when writing or stabilizing Playwright tests that drive a real browser through multi-step journeys — durable locators, web-first assertions, storageState auth, trace/retries…. E2E Testing is an agent skill from ericrisco/rsc-harness. Use when writing or stabilizing Playwright tests that drive a real browser through multi-step journeys — durable locators, web-first assertions, storageState auth, trace/retries, and flakes that only bite in CI.

When should I use E2E Testing?

E2E Testing fits situations like: stabilizing Playwright tests that drive a real browser through multi-step journeys — durable locators; web-first assertions; storageState auth; flakes that only bite in CI.

How do I install E2E Testing in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill e2e-testing -a claude-code`. Or copy the skill folder (skills/e2e-testing in ericrisco/rsc-harness) into .claude/skills/e2e-testing in your project. Claude Code loads it when a task matches its description.

How do I install E2E Testing in Codex?

Run `npx skills add ericrisco/rsc-harness --skill e2e-testing -a codex`. Or copy the skill folder (skills/e2e-testing in ericrisco/rsc-harness) into .agents/skills/e2e-testing in your project. Codex loads it when a task matches its description.

Can I use E2E Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill e2e-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/e2e-testing, .gemini/skills/e2e-testing, .github/skills/e2e-testing and .opencode/skills/e2e-testing in your project.

What does E2E Testing need to run?

Going by SKILL.md and its folder, E2E Testing needs a shell for the scripts in its folder and the command-line tools its instructions call (npx). Our summary lists: Node.js; A Bash shell.

Does E2E Testing access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is E2E Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does E2E Testing use?

E2E Testing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does E2E Testing use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to E2E Testing?

Skills that share tags, products or a category with E2E Testing: React Testing (affaan-m/ECC, 274k stars), Playwright Testing (chongdashu/vibejam-starter-pack, 149 stars), Playwright Testing (chongdashu/vibejam-starter-pack, 149 stars) and Agentic Browser Testing (petrkindlmann/qa-skills, 163 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains E2E Testing?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.