Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only declare readOnlyHint=false and openWorldHint=true; the description goes far beyond by disclosing the SSRF guard rules (https only, no redirects, public addresses only, size/time caps), the generic failure message and the absence of a bypass, the async parse→chunk→embed pipeline, the shared per-user import allowance, and the embedding-key requirement.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.