Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare idempotentHint=true and destructiveHint=false, and the description reinforces and extends this with a concrete safety guarantee ('nobody can be emailed twice for the same request'), a bounded retry policy (gives up after three attempts), a fallback path, and an auth requirement ('needs a token that allows changes'). This is substantial context beyond the structured fields.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.