I've spent seven months building one, so I've thought about this more than is healthy.
What surprised me: capability was never the hard part. Models got good enough a while ago. The hard part is finishing. Getting something to still be working at 4am, recover when a page changes shape or a login expires, and leave you something usable by breakfast is a completely different engineering problem from getting it to start well.
Building on the agent side myself, and Aarav's question hit something I think about a lot from the engineering seat, not just the user seat.
From where I sit, the hardest part to build isn't the trust boundary, it's making the failure visible enough that trust can even be extended safely. Most "I'd never let it touch X" answers aren't really about the action itself, they're about the fact that when a drafting task goes wrong, you see the draft before anything happens. When a booking or a send goes wrong, you find out after, sometimes from someone else.
So as an engineer, I've started thinking the real product problem isn't expanding what the agent can do, it's shrinking the gap between an action happening and you knowing about it. A reversible action with zero visibility feels riskier to a user than an irreversible one with a clear receipt and an undo window.
Fulminare is a personal agent that does your work for you, possibly while you sleep, it gets its own computer and signs into your apps. Ask for a report, a website, a tidy inbox it does the work and hands you the finished thing.