Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the transparency burden. It discloses what the tool returns, that results are ranked, that trust and security scores are included, and that security flags must be surfaced transparently. It does not explicitly state non-mutating behavior or authentication needs, but the 'find' semantics make those less critical.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.