Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations cover the mutation profile (readOnlyHint=false, not idempotent, not destructive), and the description adds latency expectations (about 2, occasionally up to 4 minutes) plus the auto-approval behavior, which is genuinely useful beyond the structured fields. It does not mention duplicate-order or idempotency risks, which would be the remaining gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.