Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations cover the safety profile (not read-only, not destructive, not idempotent), and the description adds genuinely new context beyond them: the note is private, it surfaces on the person's profile, and the call costs 1 unit. It does not say whether notes can later be edited or removed, so it is strong but not exhaustive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.