Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only and idempotent hints. The description adds useful context: MD5 is excluded because it is broken and unavailable in Web Crypto, and LLMs cannot compute hashes reliably, making tool use necessary. This goes beyond the annotations without contradicting them.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.