Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly/openWorld/idempotent/non-destructive, yet the description adds materially more: redirects are followed, public internet only, JS-only pages fall back to server HTML (no headless browser), PDFs are text-converted, cost is $0.002/call with 10 free/day and x402 payment on exhaustion, and errors return isError without charging. These are behaviors the annotations cannot express.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.