{"record":{"id":"1aad851908b9476c","repo":"affaan-m/ECC","slug":"unsupported-remote-content-type-content-type","errorCode":null,"errorMessage":"unsupported remote content type: {content_type}","messagePattern":"unsupported remote content type: (.+?)","errorType":"validation","errorClass":"ValueError","httpStatus":null,"severity":"error","filePath":"skills/continuous-learning-v2/scripts/instinct-cli.py","lineNumber":231,"sourceCode":"            or ip.is_reserved\n            or ip.is_unspecified\n        ):\n            raise ValueError(f\"remote import host resolves to a non-public address: {host}\")\n\n    return urllib.parse.urlunparse(parsed)\n\n\ndef _fetch_import_url(source: str, *, max_bytes: int = 2 * 1024 * 1024) -> str:\n    \"\"\"Fetch a validated remote instinct file with bounded size and timeout.\"\"\"\n    url = _validate_import_url(source)\n    req = urllib.request.Request(url, headers={\"User-Agent\": \"ECC-instinct-import/2\"})\n    with urllib.request.urlopen(req, timeout=15) as response:\n        content_type = response.headers.get(\"Content-Type\", \"\")\n        if content_type and not any(\n            allowed in content_type.lower()\n            for allowed in (\"text/\", \"markdown\", \"yaml\", \"json\", \"octet-stream\")\n        ):\n            raise ValueError(f\"unsupported remote content type: {content_type}\")\n        data = response.read(max_bytes + 1)\n    if len(data) > max_bytes:\n        raise ValueError(f\"remote import exceeds {max_bytes} bytes\")\n    return data.decode(\"utf-8\")\n\n\ndef _yaml_quote(value: str) -> str:\n    \"\"\"Quote a string for safe YAML frontmatter serialization.\n\n    Uses double quotes and escapes embedded double-quote characters to\n    prevent malformed YAML when the value contains quotes.\n    \"\"\"\n    escaped = value.replace('\\\\', '\\\\\\\\').replace('\"', '\\\\\"')\n    return f'\"{escaped}\"'\n\n\n# ─────────────────────────────────────────────\n# Project Detection (Python equivalent of detect-project.sh)","sourceCodeStart":213,"sourceCodeEnd":249,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/continuous-learning-v2/scripts/instinct-cli.py#L213-L249","documentation":"Raised by _fetch_import_url when the fetched response's Content-Type header is present but does not contain any allowed token (text/, markdown, yaml, json, octet-stream). The CLI only accepts content types it can safely treat as a text/markdown instinct file. This prevents pulling binary or executable content from remote URLs.","triggerScenarios":"Server responds with Content-Type like application/x-executable, application/zip, text/html is fine (text/) but e.g. image/png, application/octet-stream variants are allowed — fails on application/pdf, video/mp4, application/x-msdownload, or empty-allowlist mismatches like 'application/x-yaml; charset=UTF-16'.","commonSituations":"The URL redirects to an HTML login page served as text/html (allowed) vs. a CDN serving image/png for a mistyped link; a server misconfigured to emit application/binary; a link pointing at an archive rather than the raw file.","solutions":["Point the import URL at the raw file (e.g. raw.githubusercontent.com instead of an HTML blob page) so the server returns text/plain or text/markdown.","Fix server MIME configuration to serve .yaml/.md as text/yaml or text/markdown.","Verify the URL is correct — a 404/redirect page often comes with an unexpected content type.","Check the header before calling: urllib request and inspect Content-Type against the allowed list."],"exampleFix":"# before\nurl = \"https://example.com/files/instincts\"  # served as application/pdf\n# after\nurl = \"https://raw.githubusercontent.com/org/repo/main/instincts.yaml\"  # text/plain","handlingStrategy":"validation","validationCode":"import urllib.request\nreq = urllib.request.Request(source, method=\"HEAD\")\nwith urllib.request.urlopen(req, timeout=15) as r:\n    ct = r.headers.get(\"Content-Type\", \"\")\nallowed = (\"text/\", \"markdown\", \"yaml\", \"json\", \"octet-stream\")\nif ct and not any(a in ct.lower() for a in allowed):\n    raise ValueError(f\"unsupported content type: {ct}\")","typeGuard":null,"tryCatchPattern":"try:\n    cli_import(url=source)\nexcept ValueError as e:\n    if \"content type\" in str(e):\n        print(\"URL must serve text/markdown/yaml/json content\")","preventionTips":["Link raw file URLs, not HTML blob or binary pages","Ensure servers serve .yaml/.md with text/* MIME types","HEAD-check Content-Type before importing","Verify the link isn't redirecting to an error/asset page"],"tags":["python","network","content-type","security"],"backgroundTag":"unsupported-operation","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}