A) connect it to a non-routable development side of the pool, so that the box is unable to communicate with the internet. I will then let it submit shares to the pool and I will have one of the getwork servers in debug mode and I will see what is sent out and what's sent back. As I found no evidence of any wireless communications on the board, and since the computer it's connected to will not be on the internet, it won't have any way of falsifying the shares submitted.
B) I will take a unit home that evening, disassemble and take more robust pictures. I will NOT be removing any heat sinks, however.
C) I will do further testing that evening on my own with a packet analyzer to see what packets are being transmitted, when and where they are going and coming from.
That's the plan as of right now, at any rate.
Please make sure at some point during the actual mining you run it on a power meter so you can get a measurement under actual mining load.
There are various ways to fake this sort of thing and match one of {rate,power} but not both. (e.g. you could use a big-fast-expensive FPGA to get 1GH/s, but if they did that they couldn't deliver on their advertised price)