Demonstrating how jsonp served with an incorrect content/type fails with the X-Content-Type-Options:nosniff header
git clone https://github.com/agradl/jsonp-content-type-example
cd jsonp-content-type-example
./run
check your console to see how the bad jsonp response is rejected by the browser