Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly=false, idempotent=false, destructive=false, openWorld=true, so the safety profile is covered and the description is not required to repeat it. The description adds auth requirements and the ownership constraint, which annotations cannot express. It stops short of warning that repeated calls append duplicates (implied by non-idempotency) or describing error behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.