I think we have different motivations. pip-compile can only fetch and install dependencies which have been declared.
For example, let's say I have a malicious yaml parser package. It should not need requests as a dependency. The odds are that a project may have requests already installed as a sub-dependency of another dependency. I can then just try and import requests in a try catch block and if available, and fetch malicious artefacts, for example. Panoptisch would report this.
Also, the usage of operating system or builtin modules such as socket, sys or importlib is not something which is analyzed by pip-compile.