Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already mark the tool as read-only and non-destructive. The description adds useful context that this is a visual picker optimized for in-chat cards, but it does not describe failure modes, auth requirements, or whether the picker is persistent. The annotations carry the main safety burden here.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.