Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
While annotations correctly flag destructiveness and idempotency, the description adds no behavioral context such as cascade effects (what happens to scheduled meetings at this location?), reversibility, or required permissions. For a destructive operation, this lack of side-effect disclosure is a gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.