Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the readOnly/openWorld/non-destructive annotations, it discloses result ordering (by recent publication, no quality ranking), input rejection rules (no CEP/neighborhood/coordinates, no distance calculation, no location inference), and result semantics (distinguishes an empty list from a technical failure). That is substantial behavioral context the annotations do not carry.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.