Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations, the description discloses that reports cannot be withdrawn, that there is no public status lookup, that secrets and private note bodies must not be included, and that content is encrypted at rest. This gives an agent meaningful operational and safety context for a destructive, admin-facing action.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.