Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint and idempotentHint, but the description adds rich behavioral detail: no wallet/signer contact, no USDC spend, ledger candidate surface with real inbound IP, and the requirement for non-VPS source_ip and run_id matching to promote a candidate to an EXTERNAL_RUN. This goes far beyond the structured annotations without contradicting them.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.