DOM Snitch: Google's passive in-the-browser reconnaissance tool
googletesting.blogspot.com
googletesting.blogspot.com
I tried it but to be honest did not find it terribly useful. They seem to be using some very simple rules for best practices (like avoiding document.write). But it's nothing more than that (yet)
I wouldn't really call them rules. The tool looks for use of dangerous JavaScript APIs and, when it detects them, it gives you more information, such as stack trace and arguments. That information should help someone determine if a particular use is insecure. Besides that it has some relatively simple logic to determine if a particular usage might be a security bug or not, which is indicated through different colors.
Everything will be turned off when you install it. Once you change settings all new tabs will open with the new settings.