Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden and excels: it discloses one-use code generation, request marking, emailing, the emailed true/false flag, code visibility only once, revocation on re-approval, and the 409 request_already_decided error. This is exemplary behavioral disclosure.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.