Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With destructiveHint and openWorldHint already declared, the description still adds substantial behavioral detail beyond them: the preview-before-execute flow gated by confirm:true, the enumerated dangerous-command refusals, the read-only mode disable condition, and caps on output and runtime. This is rich disclosure of what the tool will and won't do.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.