Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, idempotentHint=true, openWorldHint=true and destructiveHint=false, so the safety profile is covered and the description does not contradict it. The description adds the useful fact that the result includes both risks and a remediation plan, but says nothing about scan duration, breadth of the environment scanned, or cost of an open-world sweep.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.