Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare a non-destructive, non-idempotent write, and the description adds real context beyond that: the material is saved privately, and downstream asks (ask_workspace and agents) answer from it with sources. It does not address duplicate saves or what the stored item looks like, but the privacy and downstream-consumption behavior is valuable disclosure the annotations do not carry.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.