Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With readOnlyHint/destructiveHint already covering the safety profile, the description adds real behavioral context the annotations don't: rows are scoped to the calling key only, entries are sanitized summaries, idempotent replays and latency are included, and fills follow paper_execution_v1 with a disclosed execution cost. Return format is left to the output schema, which is acceptable.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.