Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description partially carries the transparency burden. It discloses the auth forwarding behavior and the 'factual label-derived' nature, but does not mention output format, rate limits, or side effects (though likely a read operation). This adds some context but lacks richer behavioral detail.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.