Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly=false, destructive=false, openWorld=false. The description adds genuinely new behavioral facts: it spans multiple projects and excludes credentials, and it imposes a concurrency constraint. It does not say where the backup is written or its format, but the additions go meaningfully beyond the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.