Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations provide only destructiveHint=true and a title, so the description carries most of the burden. It usefully discloses that the note is internal (not customer-facing) and exposes the backing endpoint POST /api/4/notes, but says nothing about permissions, failure modes, or whether notes are editable/deletable afterwards. Note the mild tension: "attach" reads as additive while the annotation flags destructive behavior, though this is not an explicit contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.