Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond annotations (idempotentHint=true), the description details idempotency_key reuse, required scopes, agent-scoped bearer key, and explicit limitations (cannot self-approve, dispatch postage, charge, destroy, or complete work). It also clarifies that the open_and_scan sample is test training, not paid OCR, providing real behavioral context that annotations do not cover.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.