Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already flag destructiveHint=true and readOnlyHint=false, so the description only needs to add context, and it does: the token is exact and single-use, calls cannot be rewritten/replayed, and the reply is a result, not an approval handle/JSON/debug internals. It doesn't detail the destructive side effect itself, but the annotation plus operation names cover the safety profile.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.