Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint and destructiveHint=false, so the safety profile is covered; the description usefully adds that listing does not mark messages read, that ordering defaults to arrival order, and that email content is untrusted data. These are real behavioral facts beyond the structured fields, though permissions and return shape are left to the output schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.