Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. 'Delete a file' correctly signals a destructive mutation, but it does not disclose that the deletion is performed via a new commit (explaining the required 'message' parameter), that the operation is irreversible, or that the SHA may be needed to avoid conflicts. For a destructive tool with zero annotation coverage, this is a significant gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.