Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only, idempotent, open-world, non-destructive behavior, so the safety bar is covered. The description adds genuinely useful behavioral context beyond that: the 100-phrase batch ceiling and the cost model ($0.15 per successful call, failed calls free). Auth handling is left to the api_key schema field.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.