Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover readOnly/idempotent/non-destructive, so the bar is lower, yet the description adds substantive domain behavior: only APPROVED-status rules carry authority and that authority is exercised via evaluate_commitment, not by reading this list. It says nothing about what includeRetired surfaces, but the safety-relevant behavior is disclosed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.