Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safety profile (readOnlyHint=false, destructiveHint=false, openWorldHint=true, idempotentHint=false). Beyond that, the description adds a genuinely non-obvious behavioral trait: the signing secret is returned only once and must be stored securely. That is valuable context the annotations cannot convey, though permissions and idempotency of duplicates are unaddressed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.