Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
readOnlyHint=true already establishes the safe-read profile, and the description adds useful context beyond it: the result is scoped to the token's own business, the call is cheap/low-risk, and it doubles as a credential/audience check. It doesn't discuss error behavior for invalid tokens, but the added value over annotations is real.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.