Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description bears full responsibility for explaining side effects. 'Configure' is vague; it does not disclose what configuration entails, whether 2FA is enabled, if any secret is returned, or any security implications. The description is too thin for a security-sensitive operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.