Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations indicate openWorldHint=false and destructiveHint=false, but do not state read-only. The description adds transparency by explaining that this is a confirmation step, that it does not produce an official certificate, and that it should not present a download link. It also specifies the workflow (summarize details, wait for explicit confirmation, then call approve). This goes beyond the annotations, though it does not explicitly state whether the tool has side effects (e.g., marking a status).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.