Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations present, the description carries the full disclosure burden and succeeds. It reveals what the tool does NOT do (no storage, no nonce, no counter, no escrow), what validation it performs (full, including the stake check), what it returns (the exact receipt the write would return), and how it must be authenticated (sign like any read). This is exemplary behavioral disclosure for a dry-run tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.