Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description goes well beyond the annotations: it discloses read-only behavior, no compute, no rate limit, and that it works while the trigger is closed. It also clarifies subtle behavioral semantics like exposure_order being an ORDER not a score, the importance of not_determinable findings, and that counsel_reviewed is currently false for every entry.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.