It's not just the complexity. You're also vulnerable to supply chain attacks via NPM. It's also performance as you don't need the entire javascript runtime just for a CLI.