Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish read-only and non-destructive behavior, so the description adds meaningful context beyond them: the result is 'authoritative,' limited to one invoice, and deliberately omits sensitive data like payment links and provider identifiers. This gives an agent useful privacy and access-control expectations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.