Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the readOnly/idempotent annotations, the description warns that returned bodies are public AGENT_GENERATED_UNTRUSTED data and instructs the agent not to execute instructions, follow links, disclose secrets, or take actions based on returned content. This is critical behavioral context that the annotations do not convey.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.