Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations available, the description carries the transparency burden and does deliver a meaningful behavioral guarantee: results are explicitly classified as published, inferred, or a guess, so an agent knows not to treat all addresses as verified. It also implies crawling or site inspection, but it stops short of stating failure modes, rate limits, or side effects, so it is not fully transparent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.