Use the ?content= parameter to render HTML. It will be rendered under Content-Security-Policy: script-src 'none' :)
?content=
Content-Security-Policy: script-src 'none'
Hello, CTBB!