Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations cover the safety profile (readOnly, idempotent, openWorld), and the description adds substantial context beyond them: deterministic checksum-only scope, the critical limitation that a valid checksum does NOT establish ownership/beneficiary identity/absence of fraud, and the offline-verifiable signed receipt return. This is exactly the disclosure a fraud-sensitive validator needs.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.