Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (readOnly=false, idempotent=false, openWorld=true), it discloses the concrete side effects and limits: it returns a Stripe Checkout link and booking link for the user to open, charges nothing itself, never pays on the user's behalf, and sends no automated email. That is exactly the context an agent needs before invoking a paid flow.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.