Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description is transparent about the failure mode (slug in use), the scope (renames the app only, not member resources), and the nature of the operation. Annotations are consistent (readOnlyHint=false, destructiveHint=false), and the description adds important behavioral details beyond those flags.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.