Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already provide idempotentHint=false and readOnlyHint=false, but the description adds valuable behavioral context: the call persists credential-use state, making it non-idempotent end-to-end, and includes a business-level replay guard (an already-retried block is not retried again). It does not contradict annotations. The additional detail about server-side derivation of eligibility, tenant, etc., also enhances transparency, though it doesn't explicitly mention destructive or safety implications beyond what annotations imply.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.