Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare read-only, idempotent, non-destructive, and open-world hints, so the description adds beyond that by stating it returns only metadata and never the bytes. It also adds the ownership constraint ('owned task's attachments'), which is useful behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.