Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full disclosure burden. It usefully discloses the output profile: the report is allowlisted and excludes tokens, state, arguments, and raw errors, which tells the agent the result is safe to surface and intentionally lossy. It omits access requirements, whether it is strictly read-only, and any rate/size behavior, so it is only partially transparent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.