Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly=false, idempotent=true and destructive=false, so the safety baseline is covered. The description adds genuinely useful context beyond that: batch size limit of 100 and all-or-nothing atomicity ("All targets must be accessible or nothing changes"), which tells the agent how partial failures behave.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.