Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations, the description discloses concrete behavior: the entry 'lands at priority 1, tagged sys:api,' and that the basket is private. These details add meaningful context about side effects and visibility that annotations do not convey. There is no contradiction with the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.