Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description marks the tool as '[L:READ]' indicating a read-only operation, which is a behavioral trait. With no annotations provided, the description carries the full burden, but it does not disclose authentication needs, rate limits, or other side effects beyond the read hint. This leaves significant gaps in behavioral transparency.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.