Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description explains the computation (emitted minus retired) and the condition for carbon_accountable, giving insight into behavior. However, it does not disclose whether the tool is read-only, requires authentication, or has side effects. With no annotations provided, the description carries the full burden but falls short on safety guarantees.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.