Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare the tool is not read-only, not open-world, idempotent, and not destructive. The description does not contradict these, but it also doesn't elaborate on the idempotency behavior or what 'queuing' entails (e.g., state changes, side effects). Since annotations already cover the basic safety profile, the description adds minimal extra behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.