Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only give the generic safety profile; the description adds the crucial upsert semantics (an existing case-insensitive label UPDATES its URL, aligning with idempotentHint=false), the validation/normalization rules (https only, bare domain normalized, javascript:/http:/IP-literal/credential URLs rejected), and a field-length limit.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.