Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations exist, so the description carries the disclosure burden. It goes beyond a one-line summary by exposing non-obvious processing details: stripping preview/demo post-sign fields, JCS canonicalisation with both ASCII escaping modes, signer recovery, and checking against manifest signers. It does not disclose failure/return behavior, but the core behavior is transparent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.