Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safety profile (readOnly, non-destructive, closed-world). The description adds a genuine behavioral detail not in the annotations: an unscoped call returns additional sections (decision_readiness, balance_validation, scout_currency_quality, data_coverage) that a scoped call does not, so the shape of the response depends on how it is called.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.