Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent, non-destructive behavior, so the safety profile is well covered. The description adds the meaningful constraint that protected files are not delivered, which is real behavioral context. However it says nothing about pagination behavior despite a cursor parameter, result limits beyond the schema max, or what a discovery result contains.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.