Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover read-only, idempotent, and non-destructive behavior. The description adds useful context beyond annotations, such as returning current kb_snapshot, determinism guarantees, and limits, and positions the tool as a self-configuration mechanism. It does not detail output format, but the risk profile is low and well-covered.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.