Set X-Content-Type-Options: nosniff
SkillSecurityx-content-type is a skill for auditing HTTP response headers on web servers and CDNs. It checks that headers follow security best practices, so an AI agent can review a server or CDN configuration and flag headers that need hardening.
Use Set X-Content-Type-Options: nosniff in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Set X-Content-Type-Options: nosniff and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Set X-Content-Type-Options: nosniff skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Have an AI agent that can load skills.
What your AI can do with it
- Audit HTTP response headers on any web server
- Audit HTTP response headers on CDNs
- Check headers against security best practices
- Identify headers that need security hardening
Getting started
- Have an AI agent that can load skills.
- Add the x-content-type skill to the agent's available skills.
- Ask the agent to audit the HTTP response headers of a web server or CDN.
- Review the agent's findings and apply any recommended hardening.
What this skill tells your AI
The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/x-content-type/SKILL.md and read by ahel’s review.
Browsers that MIME-sniff can be tricked into executing malicious JavaScript uploaded as an image — even if the server sends Content-Type: image/png. nosniff forces the browser to honor the declared type.
Quick Reference
- Set
X-Content-Type-Options: nosniffon all responses — the only valid value isnosniff - Without this header, browsers may execute a JavaScript file disguised as an image if the server serves it with the wrong MIME type
- This header is required by OWASP's security hardening checklist and the Fetch specification
- Pair with correct
Content-Typeheaders on all responses for defense in depth - Takes 5 minutes to configure and has no compatibility issues
Check
Check whether the server sends an X-Content-Type-Options: nosniff header on responses. Verify the header is present on HTML pages, scripts, stylesheets, and API responses.
Fix
Add X-Content-Type-Options: nosniff to all HTTP responses. Configure it at the web server level (Nginx, Apache) or in your application framework, and verify with curl -I https://example.com.
Explain
Explain what MIME type sniffing is, how it can be exploited to execute malicious files, and how X-Content-Type-Options: nosniff prevents this attack.
Code Review
Review server config, headers, forms, and integration points related to Set X-Content-Type-Options: nosniff. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.
For full implementation details, code examples, and framework-specific guidance,
see references/rule.md.
Rule page: https://frontendchecklist.io/en/rules/security/x-content-type
Signals
- GitHub stars
- 74k
- Forks
- 7k
- Last commit
- Oct 2026
Questions
- When should this skill be used?
- Use it when auditing HTTP response headers on any web server or CDN for security hardening.
- Does it work with any web server or CDN?
- It audits HTTP response headers on any web server or CDN, since it works from the headers themselves.
- Does it change server configuration?
- No. It audits headers and reports how they compare to security best practices; applying changes is up to the user.
Advanced
- Item type
- skill
- Key
x-content-type- Source
- github.com/thedaviddias/front-end-checklist
github.com/thedaviddias/front-end-checklist
Related picks
Skill · nvidia
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infraowasp-security
Skill · davila7
The pick for Web (OWASP)security-and-hardening
Skill · addyosmani
The pick for Web (OWASP)gws-shared
Skill · googleworkspace
More in Securitybrandkit
Skill · leonxlnx
More in Security