Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden, and it does disclose two real behavioral traits: results come from on-disk runs and are ordered newest first, plus each row carries state and cost. It still omits the read-only nature of the operation, whether results are paginated or truncated, and whether missing run directories are skipped, so it is only partially transparent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.