Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark this as read-only, idempotent, and non-destructive, so the description need not repeat those. It adds meaningful behavioral context by stating that the tool 'never returns customer data' and 'requires no credential,' which are useful safety and access insights beyond the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.