Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description must carry the full burden of behavioral disclosure. It only mentions '错误中断' (error interruption), which merely reflects the stop_on_error parameter in the schema. It does not disclose that the tool executes arbitrary remote commands, potential security implications, output behavior, or sequential execution, leaving significant transparency gaps.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.