Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already flag destructiveHint=true and idempotentHint=false, but the description goes well beyond them: it names exactly what is destroyed (tracking of all queries, list visibility), states it is reversible via restore_project, and discloses the mandatory preview/confirmation gate. This is rich behavioral context beyond the safety flags.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.