I tried to figure out how recursion worked in https://w3c.github.io/webappsec-csp/embedded/ and didn't see it. Doesn't this mean that an embedded could subvert any policy applied to it, as long as it can load itself somehow?