Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint and idempotentHint, establishing safe read behavior. The description adds value by detailing exactly what content the user can expect (discussion, check, fix, severity, NIST mapping, SCAP-automatable), which sets proper expectations. No contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.