Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark readOnlyHint=true and destructiveHint=false, and the description further explains that it detects expired, self-signed, and weak certificates, and returns a grade. This adds useful behavioral context beyond the annotations, such as its network-based external host checking. No contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.