Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
readOnlyHint, openWorldHint, idempotentHint, and destructiveHint already cover the safety profile. The description adds modest extra context by noting the br-cnpj scheme accepts an 8-digit root or full 14-digit value. However, it does not disclose not-found behavior, whether the resolved entity is returned in full or just an entity ID, or any other runtime behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.