Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already specify readOnlyHint, openWorldHint, idempotentHint. The description adds context about return values (exploitability likelihood, affected cloud services, threat intelligence) and async behavior. No contradictions; description enhances transparency beyond annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.