Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations provide readOnlyHint=true, and the description adds meaningful context beyond that: it discloses that protected system accounts are rename-only, that the tool shows QuickBooks provisioning status, and that the org_id must match the key's org or the request is rejected. This goes beyond the annotation's basic read-only signal.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.