Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the readOnly/idempotent/openWorld annotations: discloses pricing ($0.001/call, 10 free/day, x402 payment-required result), error behavior (isError, not charged), matching semantics (longest match, Allow beats Disallow, wildcards), and the missing-robots.txt default.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.