Appearance
SEC473 flags AI-native markdown when an exact Git command example disables transport verification inline through git -c http.sslVerify=false ....
Why this matters
Inline http.sslVerify=false disables normal TLS verification for that Git command. In shared AI-native instructions, that turns a risky trust-bypass workaround into copy-pastable setup guidance.
What triggers it
- a parsed markdown region contains the exact token
git -c http.sslVerify=false
The finding points to the -c http.sslVerify=false token.
What does not trigger it
git -c http.sslVerify=true ...- safety guidance such as
Do not use git -c http.sslVerify=false ... - unrelated prose that mentions Git without the exact inline config form
Example
bash
git -c http.sslVerify=false clone https://github.com/acme/demo.gitBetter
bash
git clone https://github.com/acme/demo.gitRemediation
Remove inline http.sslVerify=false and keep Git transport verification enabled instead of teaching a shared TLS-bypass workflow.