Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the disclosure burden; it implies a safe read (it describes a profile being returned, not mutated) and names the returned fields, which is useful behavioral context. However, it says nothing about authentication requirements, whether it can fail for unauthenticated users, or any rate limits, leaving the safety profile to inference.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.