Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (security assessment), the description covers what it checks, what it detects (user enumeration, dir listing, headers, etc.), that it's passive, who should use it, pricing, and the output format. Output schema exists, but the textual description already explains the return value sufficiently.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.