You are right, and thank you for the precision. I checked the 2025-03-26 schema and ToolAnnotations is there with all four hints, so "no read-only mode, no scoping" is simply wrong as written. I will correct that paragraph. The schema comment is even blunter than the spec page you quoted: "Clients should never make tool use decisions based on ToolAnnotations." So the flag exists, and the spec itself tells clients not to trust it. Which lands exactly where you put it: the annotation is advisory, the two-config separation is the only thing that actually binds. Taking the point about annotating anyway. If some clients surface destructiveHint in a confirmation UI, that is free safety for the users on those clients, and it costs nothing for the ones that ignore it. Good to hear lesson four matched. The attention-tax framing is better than mine.