It's good to have a fast check for these things, but you realize how simple that stuff is to spot, right? Insecure cookies and HTTPOnly (which: HTTPOnly is a bit of a band-aid; it's not a vulnerability not to have it) are trivial regexes on set-cookie headers; methods is something you can do with curl and a shell script.
If you're spotting these kinds of things only after using a 3rd-party tool, consider whether this is the kind of stuff you want to build into your integration testing.
Sorry! I know you do (for the benefit of the thread: I've been talking to 'borski for awhile about Tinfoil). I'm not commenting about Tinfoil so much as developers who are surprised to not be using secure cookies. :)