Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the thin annotations (openWorldHint=false, destructiveHint=false) by disclosing synchronous execution, what queued_count and failed_count mean, how FAILED holdings should be reported to the user, and the critical idempotency caveat that re-running duplicates already-rendered SAFEs for every holding, not just the failed one.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.