Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full load and does deliver key behavioral facts: the proof-of-work must run on the caller's machine, not server-side, and the tool's response is a challenge plus instructions rather than membership. That is exactly the non-obvious behavior an agent would otherwise get wrong. It stops short of describing the post-challenge flow, rate limits, or persistence of the entry.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.