Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the readOnly/openWorld/destructive annotations, the description adds substantive behavioral disclosure: every fact remains labeled caller-supplied and unverified, and the tool does not research, infer budget or buyer intent as fact, draft outreach, access private data, persist input, or take action. This is rich, specific context that helps set correct expectations. No annotation contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.