Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only, idempotent, non-destructive, open-world behavior, so the safety bar is covered; the description goes further by disclosing that fallback rows are synthetic and flagged demo: true, instructing the agent never to present them as real ads, and spelling out the auth path (OAuth or Authorization: Bearer acd_live_ key).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.