Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare readOnly and non-destructive, and the description adds substantial behavioral context: it states that completeness must not be treated as authorization, and imposes strict privacy constraints ('consented, data-minimized, redacted or aggregated evidence; never raw private interviews, secrets, credentials, or personal identifiers'). These go beyond the annotations and clarify important safety boundaries.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.