Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish the tool as read-only, idempotent, and non-destructive, and the description adds meaningful behavioral context beyond those: it returns a signed Ed25519 attestation, includes a Lean 4 NDVI proof, is compliance-relevant, is not a tradable credit, and costs £150 per call. The 'Returns signed attestation' phrasing does not contradict readOnlyHint because it describes an output, not a persistent state change.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.