Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the transparency burden. It does disclose the main analytical behaviors (loop detection, cost breakdown, stuck-state classification, fix recommendations), but it does not explicitly state that the tool is read-only, describe any side effects, or mention permissions/rate limits. This leaves some behavioral aspects implicit.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.