Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only say the tool is not read-only, not open-world, not idempotent, and not destructive. The description adds meaningful behavior: default invite scope is read_write, other assistants can read and write, and the return value is the room's address. This goes well beyond annotation hints, though it does not cover edge cases like duplicate names or failure behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.