audit agent failed dismissing cookie banner before scan
Fixes audit agents blocked by cookie banners by adding a detect-choose-verify consent strategy. Use it when the agent cannot get past consent dialogs. Not for banners the agent should audit rather than dismiss.
audit agent failed dismissing cookie banner before scan - how to fix it
TL;DR
Give the agent a consent-banner strategy with a recorded choice: detect common banner patterns, click reject (or accept per policy), verify it disappeared, and only then scan. A banner left open covers content and poisons the audit. One line of why: consent banners are overlays that block interaction and change page state, so scanning with one open audits the wrong thing.
The error, verbatim
AuditAgentError: could not dismiss cookie banner, scan blocked
tried: click .accept-btn (missed), press Escape (no-op)
banner: #cookie-consent (role=dialog)
Fix it step by step
Step 1: Reproduce the block
node agent/run-audit.js --route /home | rg -i 'cookie|consent|banner' | head -5Expected: The agent stalls on the consent banner.
Step 2: Catalog the banner patterns
curl -s https://example.com/ | rg -o 'cookie|consent' | head -5Expected: Confirms the banner markup and its buttons.
Step 3: Add the consent strategy
rg -n 'consent|banner' agent/actions.js | head -10Expected: Add: detect banner, prefer reject-all, fall back to accept, verify dismissal, record the choice.
Step 4: Re-run the audit
node agent/run-audit.js --route /home | tail -4Expected: Agent handles consent and scans the real page.
Step 5: Add a regression probe
node agent/run-audit.js --smoke | tail -3Expected: Smoke run passes; schedule it so the breakdown is caught if it ever regresses.
When to use this skill
- You run an agent that scans UIs for accessibility and it hits this breakdown
- The agent's scan loop stalls, crashes, or loops on this exact failure
- You are hardening an audit agent's error handling for production scans
When NOT to use this skill
- A human runs the scan manually and it works, this is agent-harness failure handling
- The scan completes and only reports violations, use the rule-specific skills
Compatibility
Audit agent harness with DOM actions. Banner patterns vary by vendor (OneTrust, Cookiebot, custom), so pattern lists need updating. Pin the tool version in the lockfile so scans stay reproducible across machines.
Variant phrasings
agent stuck on cookie consent
Same block, same strategy.
audit blocked by gdpr banner
Practitioner phrasing.
the breakdown hits other routes too
Agent failure modes are systemic; apply the hardening to every route the agent covers, not just the one that failed.
Why it happens
Consent banners from CMP vendors render as dialogs with vendor-specific markup, and agents with one hardcoded dismiss selector fail on every other vendor. Worse, clicking accept vs reject changes page state (tracking scripts load), so the choice affects what the scan sees. The robust approach is a small ordered strategy: try known reject selectors, then known accept selectors, verify the banner is gone, and log the choice. The scan must record the consent choice as audit metadata. Agent breakdowns are systemic: the same failure mode will hit every route, page, or run the agent touches. Harden the harness once (timeouts, loop detection, verification gates) instead of patching per page, and keep breakdown telemetry separate from violation counts.
Edge cases
- Prefer reject-all when available, it keeps the scan closest to a privacy-conscious user and avoids loading extra trackers.
- Some banners reappear per subdomain, the agent needs per-origin consent memory.
- Never click blindly at banner coordinates, a misclick can accept tracking or trigger navigation.
- Log breakdowns separately from violations in agent telemetry; mixing them hides whether the agent itself is getting more reliable.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_YGozAqs687ROPjzZKKjefQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.