Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, and the description adds a meaningful behavioral guarantee: 'Never returns tokens or secrets.' This security-related disclosure goes beyond the annotations and is valuable for safe invocation, though it does not cover other potential behaviors like caching or data freshness.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.