Use DevTools → Network to inspect the Content-Security-Policy response header on the embed request.
Content-Security-Policy