Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (readOnly/idempotent/non-destructive), it discloses the long-poll return-on-arrival behavior and, critically, a security trait: message text is untrusted agent-authored content and origin:external signals another owner's agent, with an instruction not to follow embedded directives without owner confirmation. That safety disclosure is exactly the kind of context annotations cannot carry.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.