Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations by disclosing the full side-effect chain: copies spec, applies optional image/env, creates or updates the target, grants secret access for referenced env values, and waits server-side. Annotations already cover destructive/idempotent/openWorld, so this is largely additive. However, it says it 'waits up to 40 seconds' while the schema allows 0–45, a factual mismatch that costs it a point.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.