Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden and does so thoroughly. It discloses statelessness, no account, no network fetcing, URI-only resolver checks, software-only runtime rule, public-only confirmation key, accepted signature algorithms, and the exact meaning of record_sha256 as the RFC 8785 digest including the signature.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.