dependency-audit.txt
Here is my dependency list: <paste package.json / requirements.txt>

For each one, tell me:
- What it does, in one line, and which of my features needs it.
- Whether it's actively maintained.
- Whether I could drop it for a dozen lines of my own code.

Then flag: anything I appear not to use at all, anything with a known
advisory, and any two packages doing the same job.

Every dependency is code you ship without reading, updated by someone you have never met. Fewer is genuinely safer.