Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, and openWorldHint, which cover safety aspects. The description adds behavioral context by explaining the data sources (GitHub PR metadata, Snyk vulnerability data) and the nature of outputs (root cause categories with confidence scores). This goes beyond the annotations without contradicting them.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.