Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare non-read-only, non-destructive, non-idempotent, non-open-world, but say nothing about where the action lands. The description supplies exactly that context – the page opens locally on the user's machine – plus an important behavioral constraint: never request the user's password or token. That is real value beyond the annotations; it stops short only of describing what happens after login completes.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.