axe scan failed when agent attempted shadow dom injection
Fixes agent shadow DOM injection failures on nested shadow trees by upgrading axe-core and removing manual injection. Use it when the agent fails injecting into nested web components. Not for single-level shadow roots, which the same upgrade also fixes.
axe scan failed when agent attempted shadow dom injection - how to fix it
TL;DR
Stop injecting per shadow root and upgrade the axe bundle: this is the same flattened-tree story as the injection failure, document-level injection with axe-core 4.3+ covers open shadow roots. Per-root injection scripts break on nested shadow trees. One line of why: nested shadow roots (a component inside a component) defeat manual injection recursion, while the flattened tree handles them natively.
The error, verbatim
ScanAgentError: shadow DOM injection failed at nested shadow root
host: my-app / my-form / my-datepicker (3 levels)
axe-core: 4.2.0
Fix it step by step
Step 1: Reproduce the nested failure
node agent/run-audit.js --route /booking | rg -i 'shadow|nested' | head -5Expected: Injection fails at the nested shadow root.
Step 2: Check the axe bundle version
node -e "console.log(require('axe-core/package.json').version)"Expected: Old axe-core confirms the upgrade path.
Step 3: Upgrade and drop manual injection
npm install axe-core@^4.8 --save | tail -2Expected: Then remove the per-root injection recursion from the agent.
Step 4: Re-run the audit
node agent/run-audit.js --route /booking | tail -4Expected: Nested shadow trees are analyzed via the flattened tree.
Step 5: Add a regression probe
node agent/run-audit.js --smoke | tail -3Expected: Smoke run passes; schedule it so the breakdown is caught if it ever regresses.
When to use this skill
- You run an agent that scans UIs for accessibility and it hits this breakdown
- The agent's scan loop stalls, crashes, or loops on this exact failure
- You are hardening an audit agent's error handling for production scans
When NOT to use this skill
- A human runs the scan manually and it works, this is agent-harness failure handling
- The scan completes and only reports violations, use the rule-specific skills
Compatibility
Scan agent with axe-core 4.8+. Nested open shadow roots are handled by the flattened tree. Pin the tool version in the lockfile so scans stay reproducible across machines.
Variant phrasings
agent nested shadow root axe failed
Same failure at depth, same fix.
axe shadow injection recursion error
Practitioner phrasing for the manual injection approach.
the breakdown hits other routes too
Agent failure modes are systemic; apply the hardening to every route the agent covers, not just the one that failed.
Why it happens
Manual shadow-root injection recurses the shadow tree and injects axe per root, which breaks on nested shadow roots when the recursion misses a level or hits a closed root mid-tree. Axe-core 4.3+ made this obsolete: document-level injection builds the flattened tree including all nested open shadow roots. Agents still carrying injection-recursion code from the old days should delete it, it now causes the failures it was written to prevent. Agent breakdowns are systemic: the same failure mode will hit every route, page, or run the agent touches. Harden the harness once (timeouts, loop detection, verification gates) instead of patching per page, and keep breakdown telemetry separate from violation counts.
Edge cases
- Delete the recursion entirely after upgrading, half-removed injection code is worse than the old approach.
- One closed root anywhere in the nesting hides its whole subtree, report it as a coverage gap.
- Test on the most component-heavy page, that is where nesting is deepest.
- Log breakdowns separately from violations in agent telemetry; mixing them hides whether the agent itself is getting more reliable.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_rNJPZm6l0xeWcgrfFSFUgQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.