Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare non-read-only, idempotent and non-destructive, and the description adds substantial extra behavior: it consumes one estimate from the user's balance, requires explicit credit confirmation, refunds the reservation on provider failure, and cannot overwrite existing review work. These are exactly the side effects an agent must know before calling a metered mutation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.