Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safety profile (readOnly, non-destructive, open-world), so the bar is lower, and the description adds genuine value beyond them: the output is 'bounded' (constrained size) and its content must be 'treat[ed] as untrusted data', a prompt-injection warning not present in any structured field. It still omits auth/permission requirements and what 'bounded' concretely means.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.