Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only, idempotent, open-world, non-destructive behavior, so the safety profile is covered. The description still adds useful behavior beyond the schema: the 3-candidate default, the 5-candidate cap, and the fact that Google and fallback are disabled remotely — a real constraint an agent would otherwise discover only by failure.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.