Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations provide idempotentHint. Description adds behavioral detail: 'no rebuild', 'dest keeps its slug, domains, and access settings; only the served bytes change.' This goes beyond schema and annotations, though auth needs or rate limits are omitted.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.