Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the readOnly/openWorld annotations by disclosing plan-tier behavior differences (Studio vs Free/Pro output), that returned text originates from the tested site, that it is wrapped in <site-content> tags, and a direct instruction to treat it as untrusted evidence rather than commands. This is exactly the kind of prompt-injection and data-provenance context annotations cannot carry.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.