Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint and idempotentHint, so the description doesn't need to cover safety. The description adds value by explaining the opaque ID format (8 hex chars, not RFC UUIDs), entity type tags, and the relationship between companies and issuers, which are beyond the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.