Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations, the description adds real behavioral context: the challenge-publishing requirement for new domains, the asymmetry between owned and new domains, the refusal behavior for restricted credentials, and an explicit permission requirement. These are meaningful for safe invocation and are not present in the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.