Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It discloses a meaningful behavior beyond the obvious: 'Never returns key values,' which prevents an agent from treating this as a credential retrieval tool. It doesn't mention pagination or read-only guarantees, but the security-relevant detail is valuable.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.