Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly=false, idempotent=true, destructive=true, and openWorld=false, so the safety profile is largely covered. The description does add one real behavioral fact not present in annotations: the tool refuses when the target was never saved. It says nothing about the effects of the destructive state change or repeat-call behavior implied by idempotentHint, so it is only marginally additive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.