Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, destructiveHint false, idempotentHint, and openWorldHint. The description adds behavioral context by specifying return fields (CPE 2.3 URI, title, deprecation status) and the purpose of finding exact CPE strings. This adds value beyond the annotations without contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.