Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare non-read-only, non-idempotent, non-destructive, but the description adds genuinely non-obvious semantics: the call cannot charge the human, payment is explicit and human-driven, and an existing checkout is reused rather than recreated. That materially changes how an agent should treat the result, though it says nothing about expiration of the returned URL or auth requirements.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.