Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It states a read-only parsing action and mentions returning data, but it does not disclose edge-case behavior such as what happens if the PDF lacks embedded XML, whether the tool supports all versions of the formats, or any error handling. It provides basic transparency but lacks deeper behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.