Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly/openWorld=false/destructive=false, and the description usefully adds that it 'changes nothing,' that it only returns training owned by the connected account, and that it depends on an id produced earlier in the same conversation. This is meaningful context beyond the safety hints, though it says nothing about behavior when the id is stale or belongs to another account.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.