Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations supplied, the description carries full behavioral burden and meets it: it discloses statelessness, no-account operation, no-fetch behavior, resolver URI-only checking, and the specific signature handling (Ed25519 with kid, ML-DSA-65 reported unverifiable). It even specifies the hash basis, leaving little room for surprise.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.