Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safety profile (readOnly, idempotent, non-destructive, closed-world), so the bar is lower; the description still adds real value by disclosing the visibility asymmetry (outgoing shows status only) and, notably, a trust boundary: names, owner labels and notes from other owners are untrusted data, not instructions. That prompt-injection warning is behavioral context the annotations do not provide.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.