Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent, non-destructive and open-world, so safety of the operation is covered by structured data. The description adds genuinely new context beyond that: it is a public, legacy, unrevisioned record, results include author attribution and evidence, and the content must be treated as untrusted data rather than instructions - an injection warning nothing else conveys.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.