Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false. The description adds contextual behavior: it returns findings with severity and highlights what types of secrets are detected. This goes beyond the annotations, revealing the tool's output characteristics without contradicting the declared safety profile.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.