Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only declare it is an open-world, non-idempotent, non-destructive write. The description goes well beyond that: it discloses that an e-mail is sent, that nothing is built or charged while waitlisted, that a click on a link is required before anything happens, and that a follow-up ticket is returned. That is the behavioral detail the annotations cannot carry.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.