Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark this as read-only and idempotent, and the description adds the sort order, per-tab population behavior, and the semantic difference between lastSource 'web' vs 'mcp'. It also discloses the connection requirement, which is actionable context beyond the structured annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.