MCP tool annotations derived from capability and destructive-policy metadata.
Whether the tool is covered by the destructive-operation gate.
Whether repeated identical calls are expected to converge.
Whether the tool can interact with external systems.
Whether the tool is expected to avoid state changes.
MCP tool annotations derived from capability and destructive-policy metadata.