Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already convey that this is a non-read-only, destructive operation, so the agent has the core safety signal. The description does not add detail about the replaceExistingPhoto side effect, though the schema documents it; this is a minor gap rather than a contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.