Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full behavioral burden and does not meet it. It implies a read of the caller's own data but says nothing about authentication/scope (only that it is the 'signed-in employee'), what happens if no shift is assigned, or the shape of the returned data.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.