Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations: it discloses that the returned URL needs no extra API key, that links expire after 15 minutes, that they must not be shared, that read status is left unchanged, and that no attachment analysis is performed. These are exactly the operational facts an agent needs before handing a URL onward.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.