Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly/idempotent/non-destructive, but the description adds substantial behavioral context beyond them: the response is untruncated, carries a concrete size benchmark (800,000 characters, ~200,000 tokens), and warns this can exceed most models' context windows. That is exactly the kind of risk disclosure an agent needs before invoking.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.