Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (readOnly, idempotent, non-destructive), the description details auto-detection of indicator types, queries against abuse.ch feeds per indicator, per-type source coverage, per-indicator verdict with sources_queried/sources_unavailable for partial failures, and rate limits. This is substantial behavioral context not present in annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.