Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (destructive, idempotent, non-read-only), the description discloses key side effects: deletion is permanent, a namespace_token is required, and the call costs $0.005 in USDC paid via x402 or a credit token. This is exactly the kind of cost and access context an agent needs before executing a destructive operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.