Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already flag destructive and idempotent hints, but the description adds substantial behavioral context: permanent deletion, inclusion of original/output/resized/reformatted files, the fired 'batch.deleted' webhook, and the required user confirmation. This goes well beyond the bare annotation flags without contradicting them.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.