Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, destructiveHint=false, openWorldHint=false, so the safety profile is covered. The description goes beyond them by specifying what is deliberately excluded (raw provider payloads, hidden reconciliation notes, credentials, private calculation internals) and by disclosing the 80-row cap plus invoice_rows_total, which are genuine behavioral traits an agent needs.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.