Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark the tool as read-only, non-destructive, and not open-world. The description adds meaningful behavioral context beyond that: the catalog is hidden from the workspace picker and exists only for MCP seeding, and it disambiguates from Hook captions. No mention of auth or pagination is needed given the simple read-only nature.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.