For file uploads, would it be okay to unlock uploading for file
extensions .txt, .reg and maybe some script formats like .py, .sh, .vbs?

I am thinking of providing file downloads for registry tweaks, as well
as an installer script for MSYS/MinGW that someone posted in the MinGW
mailing list (python).

Or is this considered a security issue since someone could replace the
script with malicious code?

