Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It reveals the transport (SSH) but not that arbitrary commands can have destructive side effects (e.g., a command like 'reboot' or config-wiping commands), what privileges the SSH session holds, or how output is returned. This is a significant gap for a tool that can run anything.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.