Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark this as read-only, non-destructive, open-world, and idempotent, and the description adds meaningful context: no API key is required, the tool only lists/recommends rather than executing anything, and tools/list is a limited subset. This fully sets expectations for side effects and invocation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.