Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover read-only and idempotency, but the description adds genuinely useful traits: deterministic output, pure function with no external calls or ML, and hashing over the exact input bytes. The only tension is openWorldHint=true versus "no external calls," though this reads as a permissive default rather than a real conflict.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.