Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare readOnlyHint=false, openWorldHint=true, idempotentHint=true, destructiveHint=false, but the description adds genuinely new behavior: it may fetch external image URLs during rendering, it is safe to retry 'unavailable' screenshots without recreating the draft, and it never publishes. The note to follow display.instruction and check screenshot.truncated is operational guidance not derivable from annotations, and nothing contradicts them.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.