Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
readOnlyHint=true already declares this is a safe read, so the bar is lower. The description adds a genuinely useful behavioral fact beyond the annotations: 'Secrets are never returned', which tells the agent it cannot harvest signing secrets here (relevant given regenerate_webhook_secret exists). It doesn't cover pagination or ordering, but the added disclosure is meaningful.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.