Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description states 'Read-only', which conveys non-destructive behavior, but with no annotations, the description carries the burden. It does not disclose other behaviors such as whether it returns only visible windows, performance implications, or any filters. It is a simple, non-destructive operation, but the description adds minimal behavioral context beyond 'Read-only'.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.