Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only, idempotent, non-destructive, open-world, but the description adds genuinely new behavioral facts: the $0.001 USDC cost per call, that it is a keyless read, and that it is byte-identical to GET /market/npm-package-risk. The explicit non-execution / non-scanning disclaimer clarifies the safety boundary beyond what annotations convey.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.