Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare non-readonly, non-destructive, non-idempotent and closed-world. The description adds genuinely new behavior: autonomous execution without a user in the chat, results surfacing in Xenition, and approval gating before anything acts in a connected app. It does not cover what happens on repeated scheduling conflicts or how the automation is later modified, which is minor.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.