Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish safety (read-only, idempotent, non-destructive). The description adds behavioral detail beyond annotations by specifying inclusion of signed-export hashes (if available) and the exact components (verdict, drivers, assumptions, evidence summary), which helps agents understand what the response will contain and its relationship to export artifacts.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.