Method: identify the exact context your input lands in, then craft the payload that breaks OUT of that context. Prove execution by making your injected JavaScript call /m03/api/solve/csp (e.g. with fetch()). No external collector needed. Server-rendered sinks also auto-mark once a value that would run is reflected/stored here.
This page ships a Content-Security-Policy header - check it with the dev tools network tab. A CSP is only as strong as its weakest directive; read what this one actually allows for script-src before assuming inline execution is blocked.