This is an example how you can use the XSS type to fuzz URLs. This one fuzzes characters after double slashes. It uses a base tag to get round the sandboxed iframe problems.
<script>window.onerror=x=>true;</script>
<base href="https://example.com" /><a href="//$[chr]example2.com" id=x></a>x.protocol === 'https:' && x.host === "example2.com" && log($[i])<a href="//0x09example2.com" id=x></a><a href="//
example2.com" id=x></a><a href="//
example2.com" id=x></a><a href="///example2.com" id=x></a><a href="//@example2.com" id=x></a><a href="//\example2.com" id=x></a><a href="//ยญexample2.com" id=x></a><a href="//อexample2.com" id=x></a><a href="//แ
example2.com" id=x></a><a href="//แ
example2.com" id=x></a><a href="//แดexample2.com" id=x></a><a href="//แตexample2.com" id=x></a><a href="//แ example2.com" id=x></a><a href="//แ example2.com" id=x></a><a href="//แ example2.com" id=x></a><a href="//แ example2.com" id=x></a><a href="//แ example2.com" id=x></a><a href="//โexample2.com" id=x></a><a href="//โ example2.com" id=x></a><a href="//โกexample2.com" id=x></a>