You know what would be a great feature? CTR Encryptor! Ability to ENCRYPT things would allow me to create custom system titles. Sometime after 7.x firmware, retail encryption was required for anything installed on sysnand. (that and Sky3DS users might be able to use Sky3DS for rom hacks on CFW. Slot-1 requires retail encryption unless you are using Gateway mode and the Gateway card (or the equivalent clone).
I imagine all you'd have to do is encrypt the CXI, then maybe fix some hashes and modify the exheader so the correct encryption flags are set. (since homebrew and such would likely either be using zero key encryption or are not encrypted at all. Zero key encryption only works on Gateway mode as I recall, so most homebrew probably isn't using zero key)
Arm9loaderhax may become a thing in the future, so ability to have something like FBI installed to sysnand (as an independent title and not injected into Health & Safety) would be neat because it would survive system formats.
I also made a modified System Settings app for 9.2 users using a downgraded MSET. But I can't have it install it to sysnand due to not being able to encrypt it, I had to jurry rig it to install to SD. The result it's a bit buggy as you can imagine as the system crashes when you exit it. (though that doesn't happen if you launch it from DevMenu/FBI instead. But like with other system apps I had repacked to run from SD, games fail to boot after using a system app repacked to run from SD. I have no idea how BigBlueBox got BBM to boot from SD without causing this bug.

)
Some system apps that try to restart the console when exiting (MicroSD Manager being a notable example) can't if run from SD. Not sure why. If my repacked system apps didn't cause game loading to hang that would have been a neat feature.

(though for some mysterious reason, my repack of MicroSD Manager does not cause games to hang like the rest)