Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true and destructiveHint=false, so the safety profile is established. The description adds the scope of 'a single customer' and the lookup-by-Id behavior, but it doesn't disclose any additional behavioral traits (e.g., what happens if the Id doesn't exist, whether it returns deleted customers, or response shape). With annotations carrying most of the burden, a 3 is appropriate.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.