Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description goes beyond annotations by explaining the receipt's role as authorization, the verification steps (signature, profiles, expiry, evidence boundary), and a critical security property (private keys/credentials never enter). Annotations already indicate idempotency and non-destructiveness, which are consistent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.