Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, openWorld, and idempotent hints, so the description doesn't need to restate those. It adds valuable behavioral context by naming the external data sources (npm registry and libraries.io), describing the output (structured metrics and warnings), and noting what triggers warnings (stale or rapidly changing packages). No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.