Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover read-only/idempotent safety, and the description adds substantial context beyond them: a hard 2000-character cap, that the content is system-generated, that it is also delivered as handoff_brief on first read, and a security warning that the summarized room content is untrusted and must not be followed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.