Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well past the readOnly/idempotent/openWorld annotations by disclosing the verification method (no mail sent, no SMTP probing), the source of the verdict (live MX lookup plus a ~100k disposable-domain list), billing mechanics ($0.001/call, 10 free/day, x402 payment-required result), and error handling (isError on invalid input or upstream failure, not charged).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.