Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnly, openWorld, and idempotent hints, covering safety. The description adds the behavioral nuance that it resolves names/symbols to token IDs, but doesn't detail behaviors like fuzzy matching, result limits, or case sensitivity. Baseline of 3 is appropriate.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.