Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish a safe read (readOnlyHint=true, destructiveHint=false, openWorldHint=false), and the description adds two things beyond them: the result is limited to 'public' data, and returned URLs must be preserved verbatim. That URL-preservation constraint is a genuine behavioral caveat not captured in any structured field.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.