Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly/idempotent/non-destructive, so the bar is lower, and the description still adds real context beyond them: the default lightweight-while-active vs full-once-settled payload behavior, provisional charges, and a trust warning that evidence is untrusted reference data. This is substantive behavioral disclosure, not a restatement of the hints.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.