Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description must disclose behavioral traits itself. It mentions gating conditions but does not state side effects, cost implications, authentication needs, or that this tool may execute arbitrary capabilities with consequential outcomes. The word 'run' implies mutation, but the description leaves important behavioral context undisclosed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.