Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description fully discloses behavioral traits: it returns evidence only (no PDF bytes), recomputes hash chains, checks linkage and contiguity, and includes raw events for independent verification. The server-computed verdict is mentioned, and trust implications are hinted. Could add side effects or authentication needs.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.