Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries full burden. It states 'List all instances' but doesn't disclose behavioral traits such as pagination, rate limits, permissions required, or what 'all' entails (e.g., filtering options). This is a significant gap for a read operation with no structured safety hints.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.