Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false. The description adds behavioral nuance beyond these: exact matching against stored fields, the optional 'sha256:' prefix, and the critical caveat that the response always reports cryptographically_verified: false. This prevents a major misunderstanding, though it doesn't cover all possible edge cases (e.g., not found behavior).
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.