Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description goes far beyond the annotations: it discloses permanent purge of review artifacts, irrecoverable worker state, stopping in-flight machines, dropping out of project cap, list visibility changes, replay behavior, non-idempotency, and owner-scoping with 404s. This is exactly the behavioral depth needed for a destructive operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.