Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden of behavioral disclosure. It does add one useful trait: 'No identifiers are retained', which is privacy-relevant and not present in the schema. However, the core behavior remains opaque: it does not state whether the operation is read-only, how inputs are processed, whether data is sent externally, or what side effects (if any) exist. For a privacy-sensitive claim, more context is needed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.