Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description goes well beyond the annotations: it discloses hard limits (20 pages, 1000 records, 16 MiB), states that partial scans are discarded, and warns that contributed fields are unverified and must not be trusted for instructions. It also clarifies that structured fields are not an injection boundary, which is important behavioral and security context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.