Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safety profile (readOnlyHint=false, openWorldHint=true, idempotentHint=false, destructiveHint=false), and the description layers on real behavioral facts: the signing secret is returned ONCE, activation requires a signed challenge echo, no customer contact fields are transmitted, and OAuth scopes are required. None of this duplicates the annotations, and 'changes buyer or order state' reinforces the mutation semantics consistently.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.