Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries full burden for behavioral disclosure. It states the action but doesn't describe what 'logging in' entails operationally - whether it establishes a session, what permissions are required, whether it's idempotent, what happens on failure, or what the expected outcome looks like. For an authentication tool with zero annotation coverage, this is insufficient.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.