Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes far beyond the annotations: discloses sandbox isolation ('no network, secrets, or database binding'), worldwide and per-client rate budgets, per-execution resource caps (20 catalog calls, read units, 2 concurrent, 5s wall, 50ms CPU, 32KiB code, 64KiB output), and language restrictions. The readOnly/idempotent hints are reinforced rather than contradicted by the 'no network/secrets' claim.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.