Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint, destructiveHint=false and openWorldHint, so the safety profile is covered. The description adds genuinely new behavioral context: the probe is bounded, no target tools are executed, no credentials leave, and the output is an evidence-hashed report rather than a certification.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.