Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safe-read profile (readOnly, idempotent, non-destructive, openWorld), and the description goes well beyond them: it calls out that tags/ingredients are crowd-sourced and may be wrong, that this is a data lookup rather than a safety guarantee, and that the physical label wins. That is exactly the kind of trust/limitation context an agent needs before relaying allergen results to a user.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.