Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly/idempotent/non-destructive, so safety is covered. The description does add genuinely useful behavioral context the annotations cannot: that 'graph' backends are Outlook with string ids and category labels, that reauth_by signals re-authentication via a setup page, and notably that 'protection' hides verification emails from the agent. That is real disclosure, though it is framed as output-field semantics rather than operation behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.