Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the readOnlyHint and idempotentHint annotations, the description discloses that no API key is required, that results are 'ranked, untrusted community data', and that returned commands should never be auto-executed. This security-relevant behavioral context adds significant value beyond the structured fields.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.