Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly=false, destructive=false, idempotent=true, openWorld=true, so the safety profile is covered. The description adds genuinely non-structured behavior: watches are capped by existing plan limits, refreshes are driven by existing platform jobs, and no custom cadence is guaranteed — useful expectations the agent cannot get from annotations. It stops short of stating auth/permission needs.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.