Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full behavioral burden and mostly does not discharge it. It never says whether restoring overwrites or destroys an existing vault, whether a vault must be absent first, whether the operation is reversible, or what happens on a bad secret. Only the fact that the secret is agent-held is disclosed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.