Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover read-only and non-destructive behavior, and the description adds the inbox content categories and cursor-based polling behavior. However, it does not disclose auth handling, ordering, rate limits, or any subtler behavioral traits beyond what annotations and schema already imply.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.