Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, openWorldHint, idempotentHint, and destructiveHint. The description adds valuable context beyond these: 'Neither surface guarantees delivery', provenance is 'exactly as recorded' and 'self_declared never means verified', and the tool operates on the 'Communication plane only'. These clarify the reliability and scope of results, which annotations do not cover. No contradiction exists.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.