Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description adds substantial behavioral context beyond the readOnly/idempotent annotations: the source route is public, ownership is verified before calling, it fails closed, other organizations' salons are reported as not found, and provider roles are organization-wide. These details could affect an agent's expectations about results and error handling.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.