I Audited My AI's Briefing File. It Had Turned Into a Diary. A developer audited the CLAUDE.md briefing file that Claude Code loads into every session and found it had accumulated 880 words of cron-job history, several stale facts, and a rule instructing the agent to write a live GitHub token into a repository's remote URL. Using Claude Code's /checkup prompt-audit, the developer applied all nine patch hunks, moving history to a non-loaded cron-history.md and replacing the credential instruction with plain `git push`, then scanned every local repo for tokens in remote URLs. Coding agents like Claude Code read a plain-text briefing file before they do anything else. Mine is called CLAUDE.md , and it sits in the home directory of the small server I run my automation on. It tells the agent who I am, what's installed, which services run where, what the cron jobs do, and the handful of rules I don't want broken. It loads into every session, whatever I'm working on. I'd been adding to it for six months. After two model releases in ten days, I ran Claude Code's new prompt audit on it /checkup prompt-audit . The audit reads your instruction files and flags text written for older models: ALL-CAPS warnings, "think step by step", rigid scripts. It writes a report and a patch and changes nothing until you say so. I expected it to find shouting. It found almost none. What it found instead was more useful, and it changed how I think about the file. The audit's main checklist is about prompting habits that used to help and now hurt. Older models needed forceful instructions to follow anything reliably, so people wrote IMPORTANT: and NEVER everywhere. Current models follow instructions closely and literally, so the same shouting makes them over-apply a rule and behave rigidly in situations it was never meant for. My file had exactly one of those: a rule in capitals about using a site-specific command-line tool only for the site it was built for. The fix was to say it at normal volume and keep the reason: "the other sites have no command center." Two other spots used capitals for emphasis, but they stated facts, not rules, so the audit left them alone. That was the whole outdated-prompting section of the report. One finding. A quarter of the file was history. The cron section was meant to list my scheduled jobs. Over the months its header had grown into an 880-word paragraph about what I'd removed : which jobs were cut on which date, why, where the backups went, the traffic numbers that made me drop three sites, which repository was left untouched. Every entry had been accurate when I wrote it. None of it was something the agent needed to do anything. Several facts had quietly gone wrong. None of these would cause a crash. They'd cause a confident wrong answer: the agent telling me "use the Gemini CLI at this path" and spending a turn finding out it isn't there. One rule was a security habit dressed as documentation. Under my blog's repository it said: "Git push requires the token in the remote URL", followed by the exact command to paste a GitHub token into the repo's config. That was true once, because nothing else was set up to handle the login. But it's an instruction, so every time the agent pushed, it would write a live credential into a plain-text file. I'd already cleaned that exact pattern out of two other repos a few weeks earlier, and the instruction file was still teaching it. I'd been treating CLAUDE.md as documentation, a notebook about my server that the agent happens to read. It isn't documentation. It's a prompt that runs every session, and every sentence in it is a sentence the model acts on. Once you see it that way, the findings stop looking like housekeeping: The audit's own guide puts it in one line: the job is to find "specific instructions that no longer fit", not to make prompts shorter. My file didn't have an old-model problem. It had the problem every long-lived config file gets: it kept accumulating and nothing ever removed anything. The patch had nine hunks, each tied to one finding, so I could take or skip them one at a time. I took all of them. cron-history.md that isn't loaded automatically. The cron header is now one line with the job count and a pointer: "read it before re-adding a removed job." The schedule itself stayed. gh auth setup-git , confirmed a dry-run push worked, and only then replaced the line with "plain git push , never put a token in the remote URL." Then I checked every local repo for a token in its remote URL. There were none. Two smaller things went too. I removed account-balance figures from a list of fallback models, since balances drift and nothing on the machine could confirm them. I also moved four skills for a framework I'd stopped using out of the global skills folder: their descriptions were loading into every project. The file went from about 3,700 words to 2,760. That wasn't the goal, just a side effect of removing what didn't belong. The audit has an explicit list of things it must not delete, and it followed it. It kept: That restraint is the part I'd have got wrong doing this by hand. My instinct with a bloated file is to cut it hard, and a hard cut removes exactly the lines that only I could have written: the reasons. The model can work out how to be thorough by itself. It can't work out why I don't trust a particular page's metrics. Some things I'm doing differently now: The file is shorter now, but that isn't the improvement. The improvement is that everything left in it is something I actually want the agent to act on.