Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes beyond the annotations (which only flag openWorldHint=true, readOnlyHint=false) by disclosing concrete operational traits: a 100MiB size cap, per-redirect validation, and the refusal to handle authentication, paywalls, or login pages. These are real constraints an agent must plan around; only the return/failure behavior is left unstated.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.