Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations carry only negative hints (readOnlyHint: false, destructiveHint: false), so the description shoulders the behavioral burden — and it delivers richly: it states the review 'does not make changes,' is billable, rate-limited per workspace, limited to one in-flight review per project, requires the disclaimer_md to be repeated, and that refusals return ok: false without starting work. None of this contradicts the annotations; it substantially exceeds them.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.