Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description claims this is a 'preparation/read-only MCP tool', but the annotations set readOnlyHint=false, indicating it is not read-only. This is a direct contradiction. Additionally, while it says it does not sign/submit/execute/cancel on-chain work, the tool name suggests cancellation of metadata, which is a write operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.