Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, openWorldHint=true, idempotentHint=true, and destructiveHint=false, which fully establishes the safe read-only nature. The description adds that results are for 'security identification' — a forward-looking context suggesting this is a lookup/precursor step. With comprehensive annotations in place, the description's additional behavioral context is reasonable and non-contradictory.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.