Set X-Content-Type-Options: nosniff
SkillSecurityx-content-type is a skill for auditing HTTP response headers on web servers and CDNs. It checks that headers follow security best practices, so an AI agent can review a server or CDN configuration and flag headers that need hardening.
Available today. Use it from your connected AI after setup.
No other account needed.
Have an AI agent that can load skills.
Then ask your AI: use the Set X-Content-Type-Options: nosniff skill
What your AI can do with it
- Audit HTTP response headers on any web server
- Audit HTTP response headers on CDNs
- Check headers against security best practices
- Identify headers that need security hardening
Getting started
- Have an AI agent that can load skills.
- Add the x-content-type skill to the agent's available skills.
- Ask the agent to audit the HTTP response headers of a web server or CDN.
- Review the agent's findings and apply any recommended hardening.
What this skill tells your AI
The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/x-content-type/SKILL.md and read by ahel’s review.
Browsers that MIME-sniff can be tricked into executing malicious JavaScript uploaded as an image — even if the server sends Content-Type: image/png. nosniff forces the browser to honor the declared type.
Quick Reference
- Set
X-Content-Type-Options: nosniffon all responses — the only valid value isnosniff - Without this header, browsers may execute a JavaScript file disguised as an image if the server serves it with the wrong MIME type
- This header is required by OWASP's security hardening checklist and the Fetch specification
- Pair with correct
Content-Typeheaders on all responses for defense in depth - Takes 5 minutes to configure and has no compatibility issues
Check
Check whether the server sends an X-Content-Type-Options: nosniff header on responses. Verify the header is present on HTML pages, scripts, stylesheets, and API responses.
Fix
Add X-Content-Type-Options: nosniff to all HTTP responses. Configure it at the web server level (Nginx, Apache) or in your application framework, and verify with curl -I https://example.com.
Explain
Explain what MIME type sniffing is, how it can be exploited to execute malicious files, and how X-Content-Type-Options: nosniff prevents this attack.
Code Review
Review server config, headers, forms, and integration points related to Set X-Content-Type-Options: nosniff. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.
For full implementation details, code examples, and framework-specific guidance,
see references/rule.md.
Rule page: https://frontendchecklist.io/en/rules/security/x-content-type
Signals
- GitHub stars
- 74k
- Forks
- 7k
- Last commit
- Aug 2026
Questions
- When should this skill be used?
- Use it when auditing HTTP response headers on any web server or CDN for security hardening.
- Does it work with any web server or CDN?
- It audits HTTP response headers on any web server or CDN, since it works from the headers themselves.
- Does it change server configuration?
- No. It audits headers and reports how they compare to security best practices; applying changes is up to the user.
Advanced
- Item type
- skill
- Key
x-content-type- Source
- github.com/thedaviddias/front-end-checklist