Google-Caja: source-to-source translator for securing Javascript-based content
code.google.com
code.google.com
You can also easily play with the Valija and ES5/3 dialect here http://caja.appspot.com
Many here are building SaaS products, and with the SaaS landscape getting ever more crowded we see a lot of SaaS integrations emerge. Have a look at freshbooks for instance. Currently these integrations are usually implemented 'server-side': the server of one web app pulls data from another web app. If we want to allow client-side integrations, that allows a JS plugin to be loaded from another app, the we need to keep security in mind (as this is on purpose cross-site-scripting). This Caja lib seems to provide proper measures to allow these kind of integrations.
It's enabled by default, and enforced on yahoo.com/my.yahoo.com http://developer.yahoo.com/yap/homepage/