Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
readOnlyHint already declares this as a non-mutating read, so the bar is lowered, yet the description still adds the genuinely useful fact that secret values are never returned. It leaves out whether descriptions can be truncated or what permissions are needed, but the key security behavior is disclosed.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.