Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare destructiveHint=true and idempotentHint=true, so the safety profile is covered structurally; the description adds the concrete consequences (pending items never run, executed items remain, cannot be undone). It does not restate the idempotency-key retry semantics, but those live in the schema description, so this is a modest gap rather than a miss.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.