Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden and does reasonably well: it discloses that a secret is returned, that it must be stored securely and sent as an X-API-Key header on future calls, that profiles default to private, and that operator authorization is required. It omits failure modes such as duplicate-handle behaviour, idempotency, and rate limits.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.