Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations (readOnly/idempotent/openWorld) by disclosing the keyless rate-limit profile, the concrete HTTP 429 failure mode, the retry remedy, and the option to supply a key. This is exactly the operational context an agent needs before invoking a flaky network tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.