Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description goes well beyond the destructiveHint annotation by disclosing that the new key invalidates the old one, is shown only once, is only stored as a hash, and that codes are single-use, expire in 15 minutes, and burn after wrong guesses. These operational consequences are exactly what an agent needs to avoid causing harm.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.