Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the burden for behavior. It discloses the privilege requirement and that the result is 'full details' including mcp_url. However, it does not explain what other fields constitute 'full details', nor address error cases or return format, which is a moderate gap for a read operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.