Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark it read-only and non-destructive, and the description adds meaningful behavioral context: newest-first ordering, empty-list normality, PII sensitivity, the forms:read scope requirement, and the exact 403 INSUFFICIENT_SCOPE remediation flow. No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.