Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Because annotations are absent, the description is the sole source of behavioral information. It explicitly labels the tool as read-only and reveals the exact SQL syntax, which is useful. However, it does not disclose authorization requirements, error behavior, or the type of result rows returned, leaving a partial outlook.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.