Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions what the tool returns (risk score, honeypot, tax, source verification) but does not state whether the operation is read-only, has side effects, requires network access, or has any rate limits. For a security scan, the read-only nature is implied but not stated, leaving behavioral ambiguity.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.