At upload time? Or by every client at download time? Or just adhoc by random users?
This does sound like an excellent way of improving automated package checks, even if it does result in some false positives and false negatives. For all sorts of packages, not just code dependencies.