Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, openWorldHint, and idempotentHint. The description adds useful behavioral context by revealing data sources ('OSSF Scorecard API and GitHub Archive') and the shape of results ('score deltas, check failures, and risk flags'). This goes beyond what annotations provide, though it does not discuss rate limits or error handling.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.