Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden of behavioral disclosure, but it offers almost nothing. It does not mention whether an active reverse shell is required, whether content overwrites existing files, size limits, encoding, or error behavior. The phrase 'via reverse shell' hints at the mechanism but provides no operational details.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.