Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations add idempotentHint=true, but the description explains exactly what that means operationally ('Exact retry key/scenario reuses the fixture'). It also discloses the deprecation state, the auth model, shared rollout switches, SQL authorization sharing with REST, and the fact that fixtures deliberately exclude real mail, charges, facility tasks, PMBs, model calls, and member samples. None of it contradicts the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.