Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description bears the full burden of behavioral disclosure. It does not state that this is a read-only operation, whether it hits the network or a local config, whether credentials are required, or anything about the return shape. Only the minimal implication of 'List' conveys safety.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.