Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations: it discloses the permission model (send permission required for a restored open autopilot event, write permission otherwise), explains that the tool sends nothing itself yet rejoins automatic reminders, and documents the nightly re-archiving side effect. These are exactly the behaviors an agent cannot infer from readOnly/destructive/idempotent hints.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.