Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations cover safety (readOnly/idempotent/non-destructive), but the description adds materially more: upstream source (Crossref, 150M+ works), pricing and free-tier quota ($0.001/call, 10 free/day, x402 payment-required result), and error semantics (isError on invalid input or upstream failure, not charged). These are exactly the operational traits annotations cannot express.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.