Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safety profile (readOnly, idempotent, non-destructive, closed-world), so the description earns credit for adding a genuinely new confidentiality contract: no raw private artifacts, no unpublished extraction output, no internal review notes, no bucket keys. That tells the agent what it will never receive and implicitly that missing data is by design rather than an error.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.