Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full behavioral burden, and it discloses nothing. It does not state whether oldPass is validated, whether existing sessions or SSH keys are invalidated, whether the change is reversible, or what permissions are required for a credential-changing mutation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.