Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations by disclosing the state machine (claimed to in_review), that the claim is cleared and the token invalidated, that submission is irreversible and only the host can return the task, that no earlier result exists to replace, that evidence is untrusted text, and that other members observe the change. Annotations already flag destructive/non-idempotent, but the description adds substantial operational detail.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.