Chris Weber's Watcher: http://www.lookout.net/2009/03/20/watcher-security-tool-a-free-web-app-security-testing-and-compliance-auditing-tool/

Watcher plugs into the Fidder HTTP proxy and monitors for all sorts of web app vulns, from the common to the obscure.

Gareth Heyes' XSS Rays: http://www.thespanner.co.uk/2009/03/25/xss-rays/

XSS Rays runs in the browser as a bookmarklet and scans for XSS on demand.