Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full behavioral burden, yet it says nothing about permanence, reversibility, cascade effects (e.g., attached certificates or dependent hosts), permission requirements, or whether confirmation is needed. 'Delete' conveys destructiveness only by connotation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.