Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish the full safety profile (readOnlyHint, idempotentHint, destructiveHint=false, openWorldHint=false), so the bar is lower. The description usefully adds that verification is against a 'signed canonical catalog' (i.e., cryptographic/authoritative rather than best-effort), but says nothing about what a failed verification yields or whether network/auth is involved.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.