Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only give a generic safety profile (readOnly false, destructive false, openWorld false), and the description goes well beyond it: it explains refusal semantics, the coupling of screenshot cap to scenario cap, and the mode switch on the retained-evidence catalog (capture-run cap vs catalog sizing, with catalog and run_limits reported separately). The only friction is 'repeated calls with the same value change nothing', which sits in tension with idempotentHint=false; read as a conservative default hint rather than a misstatement, the disclosure is still unusually rich.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.