Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
readOnlyHint=true already covers the safety profile, so the description's added value is real: it discloses that the payload is JSON:API '{ data }' and that it contains PII, which is behaviorally important for an agent handling the response (e.g. avoiding unnecessary logging). It stops short of covering auth requirements, 404 behavior, or rate limits.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.