Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly/idempotent/non-destructive safety, so the bar is lower, and the description adds real context beyond them: verification is local, nothing is stored or logged, pricing is free, and errors return isError without charge. It stops short of full disclosure (e.g. no rate-limit or output-shape notes), but the additions are genuinely useful.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.