Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare non-read-only, non-idempotent, non-destructive, but the description goes well beyond by disclosing the key prefix (zs_live_), the auth header format, that unverified accounts stay at 0 credits due to an anonymous-abuse guard, and the credit-unlock consequence of verification. This is exactly the behavioral context annotations cannot carry.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.