Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations provide readOnlyHint=true, already indicating no side effects. The description adds value by disclosing the returned data structure (diagram→threat→finding→control→requirement→remediation chain and coverage metrics), which is beyond the annotations. No contradictions, and the description complements the read-only nature.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.