Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full disclosure burden and delivers the critical traits: destructive (HIGH_WRITE), platform-enforced hard block, and confirm=true requirement. This goes beyond the schema, which misleadingly shows confirm defaulting to false. It doesn't state irreversibility or failure behavior, but the essential safety profile is disclosed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.