Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the transparency burden. It clarifies that this is a report and enumerates the health states and outputs, strongly implying a read-only operation. It doesn't explicitly state side-effect-free behavior or any permissions, but the report nature covers most risk.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.