Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare the mutation profile (readOnly=false, destructive=false, idempotent=false), so the bar is lower. 'One undoable step' adds genuinely useful context that ties this to undo_last_change, but nothing is said about partial failures across the batch or what happens with invalid ids.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.