Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond annotations, the description adds substantive behavioral detail: 'Two-phase analysis: instant pattern library scan (12 attack vectors) + Groq semantic analysis,' return values ('injection_risk 0–100, recommendation safe/review/block, safe rewritten version when possible'), and a rate limit ('50 free/day'). These details meaningfully enrich the annotation-provided read-only/idempotent profile.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.