Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no informative annotations (all hints false), the description carries the full burden and does so thoroughly: no auth required, public URL, 24-hour TTL, warning against storing secrets, and receipt verification via sha256_hash and byte length. It also explains the REST storage_url and ETag behavior, adding genuine behavioral detail.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.