Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=false, idempotentHint=false, and openWorldHint=true, so the write/open-world nature is covered there. The description adds nothing beyond that: no token lifetime, no auth requirements, no note that repeated calls mint distinct tokens. A security-sensitive credential-minting tool warrants more, but with annotations covering the safety profile this is a modest gap rather than a severe one.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.