Yes they use Camo, but that's a proxy to ensure that you don't serve JS from the same domain as github.com so that 3rd party assets have the JavaScript domain security policy applied.
I do not believe that Camo is a sanitising proxy... just a proxy.
Seriously, can we stop inventing formats that execute arbitrary code under the hood?
[a]: Embedding the SVG directly into the HTML and manipulating it using the JavaScript in the HTML is an option, but not many people do that
[b]: We can argue all we want about whether we should be making interactive images in the first place, but the fact of the matter is, either you add it to your format, or someone else will
Edit: I think I narrowed down where you were wrong! Github "raw" endpoints for repository files DOES have a sanitizing option. But that's not Camo (camo is for remote, non repo, assets (linked in comments or in markdown)).