Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, so safety is covered; the description adds the useful payload detail (name, email, phone, custom field data, optional notes), which substitutes for the missing output schema. It does not mention permission requirements or behavior when the id does not exist, keeping it short of a 5.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.