Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description must carry behavioral disclosure, but it only says 'Authenticate with Microsoft account.' It does not mention side effects like establishing a session, whether user interaction (e.g., browser prompt) is required, or how the 'force' parameter affects behavior. The parameter is mentioned in the schema but not integrated into the tool's behavioral description.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.