Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations, the description discloses that the tool is single-use, aborts at the first failed or uncertain item, and returns results rather than debug/approval-handle payloads. It does not elaborate on the destructive side effects already flagged by annotations, but it adds useful execution semantics.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.