Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description uses 'Check' suggesting a read-only operation, but the tool name 'exploit_smb' implies potential exploitation. The default 'check_only: true' in the schema hints at safe behavior, but the description does not clarify the tool's actual side effects or whether it performs any exploitation by default. With no annotations, the agent lacks clear behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.