Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description goes well beyond the readOnly/idempotent annotations by disclosing that the operation is deterministic, free, and has no character quota, and by explaining the output mechanisms (dir spans, Unicode isolates, LRM/RLM marks). It also clarifies the ordering problem it solves, giving agents a concrete model of the transformation. No contradiction exists between the description and annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.