Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The annotations only mark non-readonly, open-world, destructive. The description adds substantial behavior: fixed electorate and no early execution, visibility restrictions, options constraint, appeal creation by an excluded target, and encryption-at-rest with automatic decryption on authorized reads. This is context the annotations don't carry.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.