It seems that the usage of SHA-1 is interpreted as a security mechanism while Linus used it mainly for other reasons, such as look up speed and deduplication of objects.
You can read the original README file when Linus created git[1]:
>+TRUST: The notion of "trust" is really outside the scope of "git", but
>+it's worth noting a few things. First off, since everything is hashed
>+with SHA1, you _can_ trust that an object is intact and has not been
>+messed with by external sources. So the name of an object uniquely
>+identifies a known state - just not a state that you may want to trust.
> ...
> +Another way of saying the same thing: "git" itself only handles content
> +integrity, the trust has to come from outside.
Yes if SHA-1 is broken, then content integrity can be broken but to me it looks like Linus at the time looked it from the point of view of corruption of files instead of "malicious" files.
[1]: https://git.kernel.org/pub/scm/git/git.git/diff/README?id=e8...