Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It transparently mentions a key privacy behavior (never returns referred-customer identities), an authentication requirement (API key), and the nature of the output (counts and totals). It does not explicitly state that the operation is read-only, but 'check' strongly implies that, and the described behavior is sufficiently transparent for a simple status endpoint.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.