Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (which only indicate non-read-only, non-idempotent), the description richly discloses behavior: submits a kie.ai job, polls, copies to R2, writes URL, costs credits, and that the job continues on timeout. It also gives actionable recovery steps. No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.