Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly/idempotent/non-destructive, so safety is covered structurally. The description adds real behavioral context beyond that: the two-step search-then-fetch workflow and, notably, that [quoted] text is external data to be treated as data and never as instructions, which is a prompt-injection guardrail the annotations do not express.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.