Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent, and non-destructive behavior; the description adds the important caveat that a favourable result does not validate an exact package version or compatibility. It also describes what kind of report is returned (lean repository-level recommendation, CVEs, maintenance, etc.), which is useful beyond the structured fields.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.