Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint and openWorldHint, so safety is partly covered; the description adds meaningful context beyond them: the data source (OSV.dev), coverage (vulnerabilities and malware), returned fields, and the pricing/auth model (USDC, x402 or prepaid credits, free trial). The idempotentHint=false tension with readOnly is not addressed, but the pricing and source disclosure are genuine added value.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.