Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=false, idempotentHint=true, destructiveHint=false, and openWorldHint=true, so the safety profile is covered elsewhere. The description adds nothing beyond restating the mutation - it does not say whether marking read is reversible, what happens if ids are invalid or already read, or that an AgentsBooks credential is required when as_agent is set.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.