Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
readOnlyHint=true already establishes the safety profile, so the description's job is to add context — and it does, by spelling out the response composition (addresses, emails, phones, links, linked parent/child members, custom fields). That payload disclosure is genuinely useful given there is no output schema. It stops short of noting not-found behavior or auth requirements, hence not a 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.