Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare destructive=true and non-idempotent, so the safety profile is covered; the description adds real value by scoping the blast radius ("only the image changes; env and everything else stay"), stating the wait behavior, and warning that it replaces the running version. Minor imprecision: it says 40 seconds while the schema allows up to 45.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.