Whenever you get a chance to intercat with the application always pay close attention to inout fields you never know how and where these inputs will be used. You can totally bring your web hacking knowledge in place in this case.
You can check for various Injection attacks like SQL, nosql, command, XSS etc.