I think the things to check are:

1. Are they using cookies in a blatantly stupid way (i.e. using them to store info that the user must not be able to modify)
2. Does the app ensure that it is not...