Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only flag readOnlyHint=false and idempotentHint=false; the description goes well beyond by disclosing cost behavior ('spends credits', 'charges the quoted credits (never more)'), a 10-minute expiry, and single-use semantics ('run once'). These are exactly the traits an agent needs before invoking a billable operation.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.