Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly/idempotent/openWorld/non-destructive, so the safety profile is covered. The description still adds real behavior: it is free and keyless, it resolves tickers through EDGAR company_tickers.json, and it caps results at the 25 most recent filings. It does not cover error behavior for an unknown ticker, which keeps it off a 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.