Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false. The description adds valuable behavioral context by explicitly stating that it returns only aggregates and never exposes identifiers, contacts, tax ids, addresses, notes, or free text. This goes beyond the annotations and is critical for privacy-aware use.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.