Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the readOnly/idempotent/destructive annotations, the description reveals the connection reuse model, no-new-OAuth behavior, limited result fields, inability to mutate, cost, and a hallucination guard ('Never invent email contents'). No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.