Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description must disclose behavioral traits, but it only says 'catalog,' implying a read-only reference without stating what the tool does with the url, host, json, or zone inputs, what it returns, or any side effects. The schema's 'discarded after the check' note hints at validation behavior that the description does not acknowledge.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.