Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the safety burden, and it does so by clearly stating 'Advisory only — does not place orders,' which is the most important behavioral trait for an execution-planning tool. It also hints at the output behavior by listing the plan components. It does not mention authentication or external calls, but for a read-only planner this is a reasonable disclosure.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.