Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare readOnlyHint=false, destructiveHint=false, openWorldHint=true, so the safety/target profile is already given. The description adds meaningful context beyond that: preview-by-default and the confirm=true requirement to actually dispatch. It does not cover rate limits or failure modes, but for an email send this is solid disclosure.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.