Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safety profile (readOnly, non-destructive, closed-world), so the bar is lower. The description adds real behavioral context: results may be detected patterns 'where available' or derived from settled invoice dates, and output is timing-only with no gain/loss figures. It doesn't state coverage limits or caveats on the derived fallback, but the added context is substantive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.