Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full behavioral burden. It adds one useful trait (execution in its own configured Python/ABI process, implying isolation) but omits whether the operation is read-only, what permissions or environment configuration are required, whether it has side effects, and what the inspection yields.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.