Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses key behaviors beyond the annotations: the receipt is idempotent, Ed25519-signed, and commits to specific elements (HASHED inputs, sources, snapshot checksum, retrieval times, decision states). It also explicitly scopes the attestation as evidence only, not a clearance or legal determination. This adds substantial value beyond the readOnlyHint and destructiveHint annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.