Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
This is a model disclosure. It explains that a one-shot review machine is spawned, that it reads the checkout offline, that findings land on the Legal page, that no code change is applied automatically, and that the result carries a disclaimer_md field. It also discloses billing, one-review-per-project concurrency, 409-shaped refusals without a compliance profile, ok:false refusals with next_step, and per-workspace rate limiting. The annotations carry only basic hints, so this rich context adds real value.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.