Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden and does meaningful work: it reveals that a secret is returnedholistic, that profiles are private by default, and that operator authorization is required. It stops short of stating whether the secret is only shown once or how registration affects existing data, so it's not a 5, but it far exceeds minimal disclosure.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.