Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint/idempotentHint, so the safety profile is covered, but the description adds genuinely new context: 'installs nothing', the SSH prerequisite for mode=ssh, and that privileged-command previews are returned. It does not cover failure modes or permission requirements beyond SSH, so it stops short of a 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.