Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the readOnly/idempotent annotations, the description discloses important behaviors: it refuses full PANs, works offline, returns results only when the prefix is known, requires no wallet or API key, and has a specific pricing/authorization model. This gives the agent materially useful behavioral context not available from annotations alone.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.