Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations: it discloses a daily browser-time budget/rate limit, that it returns screenshots, that it also loads with JavaScript off, and specifies the exact fallback path when the budget runs out. The readOnly/openWorld annotations cover safety, and the description layers operational constraints on top.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.