Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full transparency burden. It discloses that the operation is read-only, free (price 0.0), and uses the NVD CVE API 2.0, which signals safety and cost expectations. It also lists the fields returned (description, CVSS, dates, references). It does not mention rate limits or error behavior, but for a simple lookup these are minor omissions.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.