Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only give readOnlyHint=true, openWorldHint=false, destructiveHint=false. The description adds: all calls are live (never report earlier results as a new check), failures must be reported as check-incomplete, the server resolves the verified primary email, and the tool does not return arbitrary identifiers, usernames, phones, raw leak records, or credentials. These are important trait disclosures far beyond the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.