Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
There are no annotations, so the description carries the full burden. It only states 'Analyze security headers,' which implies a read-only inspection but does not disclose whether it makes network requests, what output to expect, potential side effects, or any permissions needed. This is a minimal but not entirely empty disclosure.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.