Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (openWorldHint=true, destructiveHint=false), the description discloses several surprising behaviors: it rotates signer tokens so 'every link emailed to them earlier stops working,' it operates 'platform-wide, never scoped to the caller's company,' and dry_run 'reports the would-be sends without emailing, rotating, or persisting anything.' These details give the agent a clear mental model of side effects and boundaries.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.