Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare destructiveHint=true, openWorldHint=true, non-idempotent, and not read-only, so the risk profile is covered structurally. The description adds the meaningful detail that execution happens in an 'isolated sandbox' and that the program must return its result, but it does not say what constraints 'short' imposes (time, memory, tool-call budget) or what happens on sandbox failure.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.