This tester issues the exact request shape a real cross-site attacker page would produce — each one carrying no valid CSRF token — against your own live session, so you can watch the state change and confirm the finding on Progress. The detection is server-side: a state change that succeeds under these shapes is the bug.
A real CSRF PoC is served from the attacker origin. Paste the HTML you would host — a self-submitting form or an <img> — to review its shape. (It is shown, not executed; the buttons above fire the live requests.)
(nothing fired yet)