Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full responsibility for behavioral disclosure. Merely saying 'refresh the authentication token' does not explain what happens to the existing token, whether a new token is returned, if authentication is required, or if the operation is idempotent. This is a significant gap for a security-sensitive operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.