Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description adds synchronous execution, forbidden task support, and detailed output-handling instructions (use assistantSummary, don't display raw JSON, suggest next action). It aligns with annotations (readOnlyHint=true) and provides context beyond the structured fields.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.