Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the readOnly/openWorld/idempotent annotations: it discloses the data source (RDAP with rdap.org bootstrap), the availability heuristic (no RDAP record + no DNS), the young-domain flagging rule (<30 days), pricing ($0.002/call, 10 free/day, x402 payment-required result), and error behavior (isError on invalid input/upstream failure, not charged). This is unusually rich behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.