Set X-Content-Type-Options: nosniff

SkillSecurity

x-content-type is a skill for auditing HTTP response headers on web servers and CDNs. It checks that headers follow security best practices, so an AI agent can review a server or CDN configuration and flag headers that need hardening.

Available today. Use it from your connected AI after setup.

Have an AI agent that can load skills.

Then ask your AI: use the Set X-Content-Type-Options: nosniff skill

What your AI can do with it

  • Audit HTTP response headers on any web server
  • Audit HTTP response headers on CDNs
  • Check headers against security best practices
  • Identify headers that need security hardening

Getting started

  1. Have an AI agent that can load skills.
  2. Add the x-content-type skill to the agent's available skills.
  3. Ask the agent to audit the HTTP response headers of a web server or CDN.
  4. Review the agent's findings and apply any recommended hardening.

What this skill tells your AI

The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/x-content-type/SKILL.md and read by ahel’s review.

Browsers that MIME-sniff can be tricked into executing malicious JavaScript uploaded as an image — even if the server sends Content-Type: image/png. nosniff forces the browser to honor the declared type.

Quick Reference

  • Set X-Content-Type-Options: nosniff on all responses — the only valid value is nosniff
  • Without this header, browsers may execute a JavaScript file disguised as an image if the server serves it with the wrong MIME type
  • This header is required by OWASP's security hardening checklist and the Fetch specification
  • Pair with correct Content-Type headers on all responses for defense in depth
  • Takes 5 minutes to configure and has no compatibility issues

Check

Check whether the server sends an X-Content-Type-Options: nosniff header on responses. Verify the header is present on HTML pages, scripts, stylesheets, and API responses.

Fix

Add X-Content-Type-Options: nosniff to all HTTP responses. Configure it at the web server level (Nginx, Apache) or in your application framework, and verify with curl -I https://example.com.

Explain

Explain what MIME type sniffing is, how it can be exploited to execute malicious files, and how X-Content-Type-Options: nosniff prevents this attack.

Code Review

Review server config, headers, forms, and integration points related to Set X-Content-Type-Options: nosniff. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/security/x-content-type

Signals

GitHub stars
74k
Forks
7k
Last commit
Aug 2026

Questions

When should this skill be used?
Use it when auditing HTTP response headers on any web server or CDN for security hardening.
Does it work with any web server or CDN?
It audits HTTP response headers on any web server or CDN, since it works from the headers themselves.
Does it change server configuration?
No. It audits headers and reports how they compare to security best practices; applying changes is up to the user.
Advanced
Item type
skill
Key
x-content-type
Source
github.com/thedaviddias/front-end-checklist