Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations cover the safety profile (readOnly=false, destructive=false, openWorld=true, idempotent=false). The description adds genuinely useful behavior beyond that: the message lands in a shared conversation visible to the renter and facility, routing is automatic, and links are optional context. It doesn't disclose rate limits or delivery semantics, but the audience/visibility disclosure is the key thing an agent couldn't infer.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.