Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover readOnly/idempotent/closed-world, but the description adds real behavioral context: results are a selection rather than exhaustive, negative outcomes are surfaced explicitly, and locked facts must not be contradicted. It does not cover rate limits or result shape, but the output schema handles returns.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.