Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the readOnly/destructive annotations: it discloses the return shape per mime type (utf-8 text for text/csv/vcf/vcard, metadata + note for binaries with no base64 dump), the exact auth scope and connection types, that ChatGPT profiles and share tokens cannot call it, and the $0.10 cost. This is rich behavioral context an agent cannot get from annotations alone.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.