Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations, which already mark it read-only and idempotent, the description adds valuable behavioral context: it relies on a human-authenticated server record, cannot substitute model output for human authority, does not bypass Studio, and does not expose credentials. No contradiction with annotations exists.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.