Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations cover the safety profile (readOnlyHint=false, idempotentHint=true, destructiveHint=false, openWorldHint=true), and the description adds material context beyond them: a real per-call cost (0.002 USDC via x402), retry semantics that require re-sending the same idempotencyKey and payment authorization, and an explicit epistemic caveat that signed declarations do not independently prove execution. It does not describe persistence failure modes or what the stored receipt looks like.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.