Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Beyond the annotations (read-only, idempotent, open-world), the description discloses key behavioral traits: it uses live DNS, performs no SMTP probing, and therefore does not claim mailbox existence. It also reveals important operational details—pricing per call, the x-credit-token header for unlimited calls, a free daily tier, and that no wallet or API key is needed. This goes well beyond what annotations provide.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.