Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, idempotent, non-destructive and non-open-world, so the safety profile is covered. The description adds genuine context beyond that: the tool is not connected and performs no network calls, warning the agent that results are stubbed. It stops short of describing the return shape or what the stub data looks like.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.