Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description bears full responsibility for disclosing behavior. It adds context that the report is public and machine-readable, and that the SHA-256 field is only included when present. However, it does not mention error handling, whether the operation is purely read-only, or any rate limits or side effects.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.