Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden for behavioral disclosure. It only mentions the query act and tenant/uid scoping, but doesn't disclose that sensitive details require admin authorization, the meaning of response profiles, or any potential side effects. The schema descriptions cover some of this, but the description itself lacks transparency.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.