Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the behavioral burden. It discloses that the tool returns a score (0-100) and prioritized findings, and its 'scan' wording implies a read-only operation, so it is not misleading. However, it does not explicitly state that the scan is non-destructive, nor does it mention potential side effects of accepting a URL (e.g., cloning), runtime cost, or failure modes.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.