Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (which already declare read-only/idempotent/open-world), the description discloses cost and quota behavior ($0.002 per call, 10 free/day, then an x402 payment-required result), and error semantics (isError with a message on invalid input or upstream failure, and that failures are not charged). These are operational traits an agent cannot obtain from the annotations or schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.