Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the behavioral burden and includes a critical warning that messages are untrusted data and should not be treated as instructions. This goes beyond a simple read description, though it omits other details like ordering or return shape.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.