Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare the full safety profile (readOnly, idempotent, openWorld, non-destructive), so the description's job is to add context beyond that. It adds that the result is a 'failing path plus highest-leverage next steps' rather than a score, which is mildly useful, but says nothing about probing behavior, timeouts, or limits of an open-world network call.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.