Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden and does so well: it discloses SSRF protection (public IPs only), a 256 KB size cap, a 6 s timeout, a 10/min rate limit, and warns that returned text is untrusted (prompt-injection risk). These are exactly the operational constraints an agent needs before invoking.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.