Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover safety (readOnly, idempotent, non-destructive), so the bar is lower. The description adds real behavior beyond them: image-only pages are never guessed at, unavailable artifacts fall back to the approved PDF link, and the read never triggers processing. Return format specifics are left to the output schema.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.