Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent, and non-destructive. The description adds valuable context beyond annotations: the bundle's contents (hash-chained provenance, intent bindings, PQC attestations), the key property of independent verifiability without Kevros access, and the per-call cost of $0.05. This is significant extra behavioral and operational info.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.