Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish read-only, idempotent, non-destructive, closed-world behavior, so the safety profile is covered. The description adds genuinely useful context beyond the annotations: it describes the return shape (fit verdict, memory arithmetic, decode-speed range with a confidence label) and the underlying model (memory sized from all parameters, speed from active parameters). There is no mention of caching, rate limits, or how the confidence label is derived, so it is not exhaustive, but it is well above the annotation baseline.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.