Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the burden, and it does make one genuinely useful disclosure: "content-free" tells the agent the response excludes stored memory content, implying a safe, non-destructive read. It does not, however, state read-only status explicitly, auth requirements, or whether the output is cached/per-tenant, so the safety profile is still partly inferred.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.