Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true and openWorldHint=true, so safety and external-call semantics are covered. The description's only added context is that the token targets CloudFront CDN, which is useful for understanding scope but says nothing about token lifetime, caching, or whether each call mints a new token.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.