Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, openWorldHint, and idempotentHint, so the description's disclosure burden is lower. It adds context about the tool being a scanner that returns structured assessments, compliance gaps, missing data flags, and source references from CDP and GRI. However, it does not mention the async behavior (described only in schema), which is a minor omission.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.