Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It discloses that the tool returns matching binaries with specific fields (name, description, check count, severity breakdown), which is useful. However, it does not mention potential limitations like pagination, empty results, or any permissions required.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.