Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The only behavioral detail is 'No identifiers are retained,' which addresses privacy but does not disclose other key aspects like whether the tool performs network requests, modifies any state, or how it handles the provided inputs. Without annotations, the description carries the full burden and falls short.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.