Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations cover the safety profile (readOnlyHint=false, destructiveHint=false, idempotentHint=false), and the description adds genuinely new behavioral detail: the authorization requirement (owners/admins), plus the failure modes ('not found / not pending / not yours to revoke'). The stated return shape ({'success': True, 'email': ...}) is useful since no output schema exists.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.