Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare the full safety profile (readOnlyHint, idempotentHint, destructiveHint=false, openWorldHint=false), so the safety burden is covered. The description does add genuine content-level context beyond annotations by disclosing that results are trust-labelled — registry-run vs. PUBLISHER CLAIMED — and include signed attestations. It still omits anything about freshness, caching, or what happens when a capability has no benchmark data.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.