Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, destructiveHint=false, so the safety profile is largely covered. The description adds genuinely new context beyond that: the server never holds funds and never accepts a private key, recovery phrase, or note secret — an important trust boundary an agent should know before calling anything here. It does not describe what the response contains, keeping it below a 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.