Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, destructiveHint=false and openWorldHint=false, so safety and idempotency are covered structurally. The description adds one genuinely useful behavioral fact not in the annotations: results are 'limited to what is shown publicly on the site,' which tells the agent the payload may be partial or restricted. It says nothing about auth, rate limits, or failure modes.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.