Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations and no output schema, the description carries the full disclosure burden, and it does describe the payload contents (columns, numeric flags, row count, provenance banner). It never explicitly states read-only/safe semantics, but for a zero-parameter inspection call the return-content disclosure is the substance an agent needs.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.