Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond readOnly/idempotent annotations, it discloses deterministic behavior, checksum-only verification, the signed offline-verifiable receipt, and explicitly warns that a valid checksum does not imply ownership or absence of fraud. This is meaningful behavioral context not present in annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.