Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, openWorld, and idempotent behavior, but the description adds meaningful runtime context beyond those: this relies on Disify, DNS lookups, and disposable/alias checks, and the result is a live signal rather than a static local verdict. It also discloses the quota-sharing behavior of the anonymous tier. No contradiction with annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.