Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the readOnly/idempotent/destructive annotations by disclosing required auth scope, plan-tier gating, the exact degraded return ('locked' with 'upgradeUrl'), and that it consumes no quota. These are precisely the operational traits an agent needs that structured annotations cannot convey.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.