Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish the safety profile (readOnlyHint=false, openWorldHint=false, destructiveHint=false, not idempotent). The description adds genuinely useful behavioral context the annotations do not carry — the URL is short-lived and private — but it says nothing about what repeated calls do, despite idempotentHint=false, or what credentials/permissions are needed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.