Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare destructiveHint=true, idempotentHint=true, openWorldHint=true and readOnlyHint=false, covering the safety profile. The description adds only the constraint that the target must be pending, but says nothing about reversibility, failure modes, or quota cost. With annotations carrying the burden, this is a modest but acceptable addition.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.