Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare non-read-only, non-idempotent, open-world behavior, and the description adds genuinely useful operational context: the structured-data eligibility restriction and the 200 requests/day quota. Missing auth model (service-account ownership) is a minor gap given annotations cover the mutation profile.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.