Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true and openWorldHint=false, so the safety profile is covered. The description adds value by enumerating the kind of content returned (evidence links, domains, blocking methods, timeline), which stands in for the missing output schema. It says nothing about behavior for an unknown/expired incident ID, which would be the natural next detail.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.