Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only, idempotent, open-world, and non-destructive behavior. The description adds a valuable security-relevant behavioral note: profile text is quoted upstream data and should not be treated as instructions, which is exactly the kind of context beyond annotations that helps an agent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.