Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations cover the safety profile (readOnly, idempotent, openWorld), and the description adds behavior beyond them: which external sources are queried (OFAC SDN, DNS/domain-age lookups), the possible risk outputs (low|medium|high|unknown), example flags, and a per-call price with a free trial. That is genuinely useful context an agent cannot get from the annotations alone.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.