What features you want it to have? The thing you're saying is super vague, I would just say that one belongs in cloud.
If it must run things on the user's machine, it's gotta be in a rootless container and not be root inside the container. All tools belong in the container. Folder access explicitly configured by the user.
Like I already did this for my local AI: https://github.com/SamInTheShell/loom
It's not perfect or even done, but it works and it shows the security model that should be standard for aligned models we're running.
Unaligned models, absolutely different story.
Also VM is better than container for security, but containers are a bare minimum for me.
Nether service has a way to configure fine-grained access for a secondary user.
How do I go about giving the agent the ability to perform these tasks without exposing myself to the risk of unexpected destructive behavior from the agent?
If you want to design a system specifically to make sure you're not going to get stonewalled for sending me an emdash, you build and maintain a set of permissive rules for sending/reading to avoid my blacklist of people I'll never work with.
Once you got API stuff sorted, just throw a cronjob at it or build a service for that stuff.
^ There be prompts all over the place here, obviously. Realistically your MCP server will end up hacking on POP3.