Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already indicate non-read-only (readOnlyHint=false) and non-destructive (destructiveHint=false), so the mutation nature is known. The description adds one useful behavior: the signing_secret is returned once and must be used for verification. It does not disclose that the webhook is company-scoped is already in description, but it does not mention what happens on duplicates, permissions, or whether the secret is in output (no output schema). It adds slight value beyond annotations but not rich context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.