Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond annotations by disclosing that sources are read-only and never modified, that the output is returned inline as an application/pdf resource, that only whole documents are concatenated, and that failures abort rather than yield a partial merge. Consistent with readOnlyHint=false (it produces a new artifact) with no contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.