Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It explicitly discloses the operation type ('WRITE') and required permission ('requires the ADMIN role'), and explains the consequence on burn-rate alerts. This goes beyond a bare 'delete' statement, though it stops short of mentioning irreversibility or error handling.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.