Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond annotations that already declare this as read-only and idempotent, the description adds valuable context: the underlying backend (data.gov.au CKAN Action API), that no auth is required, and the exact return fields. It does not mention pagination or rate limits, but the annotations and output schema carry most of the safety burden.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.