Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses many behavioral traits beyond the readOnly/idempotent annotations: determinism, literal matching, closed whitelist, case/diacritic/Chinese-insensitivity, default/max limits, translation source differences, and licensing/attribution. This significantly aids an agent's understanding of the tool's behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.