Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, and destructiveHint=false, covering the safety profile. The description adds value by disclosing what the tool exposes (auth details, tenancy info) and explaining that it confirms attribution and tenancy, going beyond the hint annotations. It doesn't describe auth failure behavior, but for a whoami read tool that's acceptable.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.