Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description must carry the full burden of behavioral disclosure. It only says 'List', which implies read-only, but does not disclose any further behavioral traits such as pagination behavior, ordering, required permissions, or whether the list includes both paid and unpaid invoices. This is insufficient for an agent to understand side effects or access requirements.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.