Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already indicate read-only, idempotent, non-destructive behavior. The description adds useful context beyond that: it specifies what 'captured flags, arguments, value shapes, availability, risk, release metadata, and official source links' are included, and notes the input can be a stable id or full command path. This enriches behavioral understanding without contradicting annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.