Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true, so the read-only safety profile is covered by structured data. The description adds one behavioral detail — the registry is 'hashed' — implying matches are validated against stored hashes. However, it does not disclose the output shape, whether matching is exact/fuzzy, or what happens on a failed match. With annotations present, the bar is lower, and the description provides marginal but real added context; a 3 is appropriate.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.