Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. The phrase 'direct replacement' hints at a set-value mechanism rather than simulated typing, which is a small behavioral clue. However, it omits side effects, whether input/change events fire, permission or auth needs, timeout behavior, and reversibility.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.