Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full behavioral burden. It communicates that the tool flags generic names and gives concrete examples, which suggests a read-only check, but it does not explicitly state side effects, return format, or whether it validates only the root node or its entire subtree.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.