Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare the full safety profile (readOnly=false, openWorld=false, idempotent=false, destructive=false), so the bar is lower. The description usefully adds caller provenance (only the fetch shim), the CORS-workaround motivation, and that the payload is pre-built, but it discloses nothing about auth requirements, rate limits, or the effect of the relayed POST on the ingest endpoint.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.