Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, so the agent knows it is a safe read operation. The description adds the 'prefixes only' detail, which informs the user that full key secrets are not returned. However, it does not disclose pagination, ordering, or whether the list is scoped to the current user or an organization.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.