Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations exist, so the description carries the full burden. It discloses the tool opens a headed browser and mutates the address (implied by 'change'), but does not state whether the change persists across sessions, whether it validates the address, or what happens to an invalid address. The headed-browser behavior is a useful disclosure, warranting a 3.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.