Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations: it discloses that affected files are rewritten and a new version is saved (explaining the non-idempotent, mutating nature), that live changes are gated behind a subsequent deploy_app call, and that the app must have finished building first. The annotations only carry destructiveHint/readOnlyHint/idempotentHint flags; the description supplies the versioning, deploy-state, and precondition semantics the agent actually needs.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.