Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only declare the safety profile (readOnly=false, destructive=false, openWorld=true), so the description carries the async burden and does it well: durable task vs job ID, the polling endpoint per client type, and the idempotency-key recovery path for uncertain responses. It stops short of stating rate limits, whether the queued turn can be cancelled, or what happens on conflicting concurrent turns.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.