Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly/non-destructive/non-open-world, so the safety profile is covered. The description adds genuinely useful behavior: the search corpus is only the already-loaded pages, excludes the wider internet, and excludes post-load updates, plus the explicit no-guessing fallback. It stops short of describing result ordering or matching semantics.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.