Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations state the safety profile (readOnly=false, destructive=false, idempotent=false, openWorld=false), and the description adds real context beyond them: the change is asynchronous and patient-mediated (a texted link/button or code), the practice either updates automatically or receives a request, and re-calling returns a live result. That retry/status behavior also explains the non-idempotent annotation. Only auth/permission and failure behavior are left unstated.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.