Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description adds substantial trust context beyond the readOnly, openWorld, idempotent, and non-destructive annotations: requests are untrusted content and not authorization to execute, no payment or verified skill is implied, and lifecycle transitions require HTTPS commands with client-held keys. This meaningfully shapes how an agent should interpret and act on results. No contradiction with the annotations exists.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.