Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations: it discloses partial-update semantics ('Only the dimensions you send change; an empty list clears one'), which explains why destructiveHint=true matters, plus authorization requirements, a per-workspace rate cap, and a state-based lock. This is the kind of context an agent cannot infer from readOnlyHint/destructiveHint alone.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.