Ten read-only diagnostics ran against one Claude Code setup — install, memory files, extensions, hooks, permissions. Two things got changed; everything else was already healthy or had nothing safe to touch.
The install is a clean native 2.1.217, auto mode is already the default, local and checked-in memory files are consistent, and the hooks are fast. The one genuinely unused add-on was the pencil design tool connection; the biggest easy win was context, not cleanup — a rules file that loaded on every single session but only matters when editing plugins.
Native launcher at ~/.local/bin/claude resolves on PATH, installMethod agrees, no npm or ~/.claude/local leftovers, all settings files parse, no clashing agent definitions.
The pencil MCP server (a connection to a design tool) got 0 calls across 50 sessions — disabled for this project. The ~180 skills and ~100 plugins were kept: this is the maintainer's own marketplace, and a 1.4-day window can't tell "unused" from "recently installed test plugin."
No duplication between local and checked-in memory, and no behavior contradictions. The global ~/.claude/CLAUDE.md loads in every project and was correctly left alone.
Root CLAUDE.md is ~2,968 est. tokens — well under the ~40k warning threshold and mostly keep-worthy (conventions, gotchas, agent directives). The one derivable block (a directory tree) was left in: its annotations encode intent an ls can't.
The real context win. .claude/rules/marketplace.md loaded on every session (~945 est. tokens) yet only matters when touching plugins. Added paths: frontmatter so it loads lazily — matching its already-scoped sibling rules.
Hooks are fast — typical times under 100 ms (PreToolUse:Bash 73 ms median over 1,154 runs). Only rare spikes (one 33 s outlier, 1 timeout in 1,154). No hook exceeds its threshold on the median. Nothing to change.
The dominant resident cost is the ~180-skill listing, not any memory file — it likely exceeds the ~1%-of-context listing budget, which truncates entries and degrades routing. Lever: enable fewer plugins per session. Run /context for the live measurement.
On 2.1.217. The latest-version lookup was denied by the permission layer, so currency couldn't be confirmed — not retried. DISABLE_AUTOUPDATER=1 in the environment turns off background updates by choice; claude update still works manually.
"defaultMode": "auto" is already set at user scope with no project or local override shadowing it. A safety classifier approves routine actions instead of prompting each time. No change.
Nothing was allowlist-safe. The frequent denials were all writes (cat >), command substitution (cd "$(git…)"), execution (node, npm run), or things deliberately rejected. No standing pre-approval minted.
git diff .claude/rules/marketplace.md git checkout .claude/rules/marketplace.md # to revert
~/.claude.json, ~50 recent session transcripts, and the settings cascade. The only outbound request attempted was the version lookup (denied).jq merge with the server name passed as a quoted argument, and secret-bearing config was read key-by-key, never dumped.