Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description must carry safety and behavioral disclosure. It does disclose that identifiers are not retained, which is useful privacy context, but it does not say whether the operation is read-only, whether data leaves the environment, or what side effects occur. This is partial but not comprehensive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.