Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only supply the generic safety profile (readOnly=false, destructive=false, idempotent=false); the description adds the non-obvious interaction protocol — a first call returns CONFIRMATION_REQUIRED with summary and token, and only a second call with confirmed=true plus that token actually persists. That is essential behavior not derivable from structured fields.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.