Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden of behavioral disclosure, but 'Generate data retention policy' reveals almost nothing. It does not state whether the tool writes files, modifies the project, requires authentication, or has side effects. The description is effectively a restatement of the tool name and provides no behavioral context beyond the bare action.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.