Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden of behavioral disclosure, and it says nothing about whether renewal requires ACME/HTTP challenge completion, whether it replaces the existing certificate in place, whether the operation is asynchronous, or what permissions are needed. This is a meaningful gap for a mutating operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.