Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already communicate read-only, open-world, and idempotent behavior, so the description does not need to repeat those. It adds some context by indicating this is a tenant-level summary of MFA registration and passwordless capability, but it does not disclose more specific behavioral traits such as aggregation approach, data freshness, or what exactly is counted.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.