Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations supply the safety profile (readOnlyHint=false, idempotentHint=true, destructiveHint=false), so the agent knows calling it may have side effects but is repeatable. The description's 'get or generate' is broadly consistent with a non-read-only tool, but it never clarifies whether a summary is persisted, how costly generation is, or when generation is triggered.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.