Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare this is a non-read-only, non-idempotent, open-world write. The description adds only the word 'private' to signal recipient-only visibility; it says nothing about delivery timing, whether messages are recallable, error behavior for unknown identities, or rate limits.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.