Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly=false, idempotent=true, destructive=false, and openWorld=true. The description adds genuinely new behavioral context: that the user drives a provider login/consent flow and that social passwords must never be requested. Idempotency-key reuse partially overlaps idempotentHint but reinforces the correct call pattern.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.