Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Adds substantial behavior beyond the annotations: restored messages are marked unread, the operation is safe to repeat and to run concurrently, the orphan fallback targets INBOX, and it declares the permission model ("Needs read and modify; every plan"). This exceeds the idempotent/destructive hints already provided.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.