Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations exist, so the description carries the full behavioral burden. It does disclose that the tool is a 'catalog entry' and runs in 'your Kuudo deployment, not here,' which is useful but incomplete. It does not mention auth, return behavior, errors, or whether invoking it locally is expected to fail.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.