Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (readOnly/idempotent/openWorld/non-destructive), the description discloses substantive constraints: no message text, ciphertext or keys accepted, no reply sent, and that sender/recipient DIDs are retained in the DM rail. These privacy and scope facts are exactly what an agent needs and are not in the structured fields.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.