Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond annotations, the description discloses non-obvious behaviors: input sanitization (URLs, wallets, payment header names stripped), rejection of extra keys, rate-limiting on discovery pulses, free-versus-paid behavior ('Never charges, never runs research'), and the shared 10-call trial across paid tools. This substantially exceeds what annotations (readOnly, idempotent, non-destructive) convey.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.