Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare idempotent, non-destructive, closed-world behavior, and the description adds genuinely new context: results are 'retained' evidence, expired results raise an error rather than returning stale data, and the caller must preserve coverage/version/warning metadata. The only tension is that 'Retrieve' reads as a pure read while readOnlyHint=false, but that is a conservative default rather than an outright mutating claim. No auth or rate-limit detail is given.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.