Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full transparency burden. It reveals the guarded nature ('confirm=ALLOW_TWINCAT_RESTART'), indicating a safety-conscious operation. However, it does not disclose side effects like stopping PLC programs, network interruptions, or state changes to the runtime system, leaving gaps in understanding the full impact.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.