Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full disclosure burden. It explicitly states read-only, silo-scoped, and provenance-stamped outputs with who/source/trust, which are meaningful behavioral traits. It doesn't detail edge cases, rate limits, or failure modes, but the core side-effect and result characteristics are disclosed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.