Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description must disclose behavioral traits, but it only says 'List firewall rules for a VM.' It does not mention whether this is read-only, requires specific permissions, what the output format is, or any side effects. For a simple read operation, some behavioral context is still expected.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.