Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark it read-only, and the description adds behavioral context beyond annotations: terminal-state handling, default/max timeout, the instruction not to raise the timeout to keep looping, and post-result requirements like not sharing a previous viewer_url and showing concurrency_notice. No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.