Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare readOnly/idempotent/non-destructive and the description's 'READ-ONLY' is consistent, not redundant filler. It goes well beyond the annotations by disclosing ownership-conditional behavior (config health only for departments you own), the not-found collapse, and precisely what the health check reports (dropped/refused members, deliberately omitted package parts).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.