Audits a project's dependency manifest (requirements.txt, pyproject.toml, package.json, Cargo.toml) for supply-chain and maintainability risks: unpinned or wildcard version specs, duplicate package names, uncommitted/absent lockfiles, dev dependencies declared as runtime, and unreproducible installs. Use when the user asks to check dependency hygiene, harden a supply chain, review a PR that changes dependencies, prepare for a security review, or wants a dependency manifest made reproducible and auditable.