How to make agents more powerful in NixOS
One of the biggest issues I'm seeing with agents driving NixOS is the lack of sudo. Now this makes sense, you don't really want an agent to control the configuration of your system, what if it breaks something? So I propose: have the agent work in a NixOS VM! They can clone your repo, make and test the changes in a safe, disposable environment and then push it to origin for you to roll out to the actual hosts!
You already have some instuctions somewhere on how to spin up VMs in NixOS. You just need to figure out a good workflow to drive agents within it.