Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description must reveal behavioral traits. It warns that returned text is untrusted data, which is a useful behavioral note. However, it does not disclose whether the tool is read-only, requires authentication, or any side effects. The warning adds value but is not comprehensive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.