This is an example how you can use the XSS type to fuzz URLs. It uses a base tag to get round the sandboxed iframe problems.
<script>window.onerror=x=>true;</script>0x0D
<base href="https://example.com" /><a href="/$[chr]/example2.com" id=x></a>x.host === "example2.com" && log($[i])<a href="/0x09/example2.com" id=x></a><a href="/
/example2.com" id=x></a><a href="/0x0D/example2.com" id=x></a><a href="///example2.com" id=x></a><a href="/\/example2.com" id=x></a>