Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations by disclosing the excerpt cap of 203 characters and that it may be truncated, and it explicitly delimits what is NOT returned (complete instructions, account data, private/paid content). The annotations only cover safety (readOnly, idempotent), so this content is genuinely additive.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.