Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description adds substantial behavior beyond the readOnly/idempotent annotations: rows are sorted by impact, the list matches the customer dashboard, and each row includes the fix state, the reason a draft may be absent, live finding statuses, and nextAction. It also signals that the full proposal is available elsewhere, which helps the agent set expectations when invoking this list.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.