Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already carry readOnly/openWorld/idempotent/destructive context, so the bar is lower. The description adds that this is the legacy path, costs $0.05 per cert, and must be followed by sqlguard_verify, but it does not explain what happens when the cert is issued or what constraints apply. There is no contradiction with the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.