Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent, non-destructive, open-world behavior, but the description adds genuinely useful context beyond them: the runtime 402 challenge is the payment authority, provider text is untrusted data, and the tool 'never signs or pays.' These are meaningful safety/trust disclosures, though return/pagination mechanics beyond x402Cursor are not fully detailed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.