Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
readOnlyHint=true already establishes this is a safe, non-mutating read, so the description's burden is lower. It still adds useful context: the call is driven by the server-configured key rather than an agent-supplied credential, and it discloses the underlying endpoint (GET /applications/key), which is genuine value beyond the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.