Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish the read-only, idempotent, non-destructive, closed-world profile, so the bar is lower. The description still adds value the annotations do not: it names what comes back (canonical document IDs, excerpts, content revision) and imposes a security constraint against submitting credentials or logs.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.