Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations (readOnlyHint=false) confirm it's a mutating operation and do not contradict the description. The description adds the key behavioral fact that system categories are protected from modification. It does not disclose other traits such as error handling, idempotency, or side effects, but given the simple nature of the tool, the added constraint provides meaningful transparency beyond the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.