The renderer follows CommonMark 0.31.2 the way the specification itself lays out, in two passes, and with GitHub extensions off and raw HTML allowed, every one of the spec’s 652 examples produces its reference HTML exactly. The first pass reads the text line by line into blocks. Block quotes and list items are containers, and a line stays inside one only if it carries that container’s marker: a > for a quote, enough indentation for a list item. A line without the marker can still continue an open paragraph, which the spec calls laziness, and is why an unindented line under a list item joins its text. Link reference definitions are collected as paragraphs close, so a link can use a definition written further down. The second pass turns each block’s text into inlines, with the spec’s delimiter-run rules for emphasis: that is why snake_case_name stays literal while un*frigging*believable turns italic.
With GitHub extensions on, the parser adds what the GFM specification defines and cmark-gfm, the library GitHub runs, implements: tables with alignment colons and \| for a literal pipe, strikethrough with one or two tildes, task list items, bare www., http:// and https:// addresses and email addresses turned into links with trailing punctuation left out, and, when raw HTML is allowed, the tag filter that escapes <script>, <style>, <iframe> and six other tags. Each heading also gets GitHub’s anchor id: lowercase, punctuation removed, spaces turned into hyphens, and -1, -2 added to repeats, so a link written for GitHub such as #install points at the same heading here. Not supported, because GitHub adds them on top of GFM rather than GFM defining them: footnotes, alerts such as > [!NOTE], emoji shortcodes, math, Mermaid diagrams and @mentions.
CommonMark does not sanitise anything: raw HTML passes straight through, and javascript:alert(1) is a valid link destination. So by default raw HTML is shown as text, and javascript:, vbscript: and data: destinations are removed, apart from data: URLs for PNG, GIF, JPEG and WebP images; a warning counts each. Allowing raw HTML gives you exactly what CommonMark specifies. Either way the preview is drawn in an iframe with an empty sandbox attribute, so no script in it can run and it cannot read or reach this page. The HTML you copy is not sandboxed. If other people’s Markdown ends up on your site, sanitise the output there with an allowlist sanitiser rather than relying on the renderer.