Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=false, idempotentHint=true, destructiveHint=false, and openWorldHint=false, so the mutation and safety profile is largely covered. The description adds that the operation attaches a property or watch folders, but says nothing about auth requirements, what happens to previously set properties/folders, or how removeFolderIds interacts with addFolders.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.