Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the behavioral burden. It mentions 'recompute' (suggesting a read-only verification) and explicitly states 'Any party can audit,' which implies no special permissions. However, it does not disclose potential costs, rate limits, or side effects, leaving some gaps.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.