Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond annotations (readOnlyHint, idempotentHint, destructiveHint false), the description adds 'Execution: synchronous', 'Task support: forbidden', and detailed instructions on handling returned JSON (never display raw JSON, use assistantSummary, suggest next action). These are meaningful behavioral disclosures not present in structured annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.