Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
readOnlyHint=true already tells the agent this is a safe read. The description adds useful context that the response includes lines, supplier and totals, but says nothing about auth, errors, or behavior for a non-existent Guid. With annotations covering the safety profile, a 3 fits.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.