Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only, idempotent, and non-destructive behavior. The description adds a genuinely valuable behavioral caveat: a DID in the query is not sufficient proof, meaning callers must provide a proper controller-key proof or valid auth token. This goes beyond what annotations provide and helps prevent failed or unauthorized calls.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.