Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already establish the safe read-only, idempotent profile, so the bar is lower. The description goes well beyond them by disclosing that coverage is limited to the 20 most recent notices, that a no-match is not evidence of product safety (false-negative risk), and that retrieved text should be treated as data rather than instructions — a genuine prompt-injection warning.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.