Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description goes well beyond the annotations (readOnly, idempotent, openWorldHint) by disclosing specific behaviors: deterministic output, a pre-resolved signed CPG-404 record for unknown objects inside the resolved universe, a typed error outside it, and 'nothing is signed at request time'. These details about error handling and determinism are valuable and not covered by annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.