Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only declare the safety profile (not read-only, not idempotent, not destructive). The description adds real behavioral context beyond them: no email/credentials are requested, the token is the sole access credential, and losing it forfeits the library unless the account already claimed it. That is meaningful consequence disclosure. It stops short of stating rate limits, expiration, or whether repeated calls create separate guests.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.