Notes/suggestions, in the interest of helping you get better at Ansible. I hope you find them helpful:
* It leaves your Apache bound on all interfaces, exposing where your files are really hosted. Security fail. (And because of the port conflict I doubt it even works in its current state.)
* It doesn't even work, due to the double "command" in "add keys". Only the second one will actually be run. (It's obvious you never tested on a fresh system. Learn about Vagrant next. It also has super-easy ansible integration. That fits the scenario really well too. Wouldn't that be awesome? "vagrant up" from any machine, wait a minute, and you have an .onion server in the Tor network?)
* Please spend 10 minutes and read the module list at https://docs.ansible.com/ansible/modules_by_category.html completely and use them. If you have to use "command" tasks (seldom the case), at least implement "changed_when" and think about if you need "when" and "failed_when". Also consider --check mode. You used command in cases where you could have used: apt, apt_repository, apt_key, service,
* Use the long key id in the --recv command too. The short will work even when there are conflicts, but it'll leave the additional (probably malicious) key in your local keyring, which may or may not confuse you later.
* The apparmor restart should be done in a handler, conditionally the config actually being changed. It also should use the "service" task.
* /home isn't the right place. Read the Filesystem Hierarchy Standard. Put the directory somwhere under /var or /srv.
* Add some blank lines for readability.
* As it is, your play isn't really reusable and not modular at all. It's ok since your intention clearly was just to show how easy it was to get Tor running. But if you want you could still turn it into a role.
* "state=directory owner=debian-tor mode=0700 recurse=yes" isn't really a good idea; it'll make all files executable too.
Getting automation right (whether via ansible, puppet, or whatever) requires careful attention to detail.