Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark the tool read-only, idempotent, and non-destructive, and the description adds substantial context beyond that: the artifact is 'cache-frozen,' candidates use 'only earlier observations,' execution is 'next-open' with costs, and weak periods or underperformance are deliberately retained. This gives agents a clear model of what the operation does and does not do.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.