Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish the safe read profile (readOnlyHint, destructiveHint=false, closed world), and the description adds substantial non-obvious behavior: the financial_details:read scope requirement, that context-only evidence carries no personal number, that notes are omitted/redacted unless include_notes=true, the $0.05 cost, and API-key requirement. It also discloses the resolve_contact alias accepted at tools/call, which is operationally important.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.