Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare destructive=true, idempotent=false, and openWorld=true, but the description adds cost and side-effect detail the annotations cannot convey: it spends one autopilot credit (or a Plus subscription slot), mails the guests, requires the send permission, and cannot be undone. That is exactly the extra context an agent needs before a costly, irreversible action.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.