Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare the tool as read-only, open-world, idempotent, and non-destructive, covering safety. The description adds the specific return fields (schema, geometry, record count, capabilities), which is useful but does not disclose potential latency, authentication requirements, or failure modes. This meets the lower bar set by annotations but adds only modest context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.