One morning the Mac that runs our agent fleet started to stutter. I checked: 16 GB free on a 926 GB disk, and swap sitting at 94% of its ceiling. The first thing anyone does in that situation is run to the Downloads folder. So I did. Downloads, Documents and Desktop together held 2 GB. Less than a quarter of one percent of the disk.
The space was somewhere else entirely — in places no off-the-shelf cleanup tool looks, because they do not exist on an ordinary computer. They exist only on a machine where Claude Code agents work all day. Here is what we found, what is safe to delete and what is not, and how we turned the cleanup into a routine that runs by itself every night.
What was actually taking the space
After an hour of measuring, we had a table nobody expected:
- Git worktrees — most of the 233 GB under the code folder. 774 directories named
*-wt-*, up to 1 GB each. Every agent that picks up a task creates a linked worktree of the repository, works in it, opens a pull request — and never removes it. 500 of those directories had not been touched in over a week. - Leftover clones from plugin installs — 34 GB. 937
temp_git_*directories in Claude Code's plugin cache. Each install clones the repository, and nothing cleans up afterwards. - The agents' browser profiles — 7 GB. 46 Playwright profiles, one per site an agent signs in to. Half of it Chromium cache that regenerates itself, half of it login state that must never be touched.
- Xcode build output — 6 GB. DerivedData, rebuilt on the next build.
- Claude Code session transcripts — 13 GB. Every session is saved. Claude Code prunes them itself via a setting called
cleanupPeriodDays, which defaults to 30 days.
Notice what is not on the list: photos, videos, personal files. Nothing a human created. All of it is a by-product of agents working correctly — with nobody tidying up after them.
Measure first, delete second
The temptation is to start deleting. We resisted, and two things saved us.
First: an "old" worktree can be the only copy of real work. An agent that stopped halfway leaves behind changes never committed to git, or commits never pushed to the server. From the outside it looks exactly like an abandoned directory. Before every removal we checked four things: the directory had not been touched for a week, no process was sitting inside it, git status was completely clean, and its last commit already existed on the remote — or was the head of a pull request that had already been merged. Only when all four held was the directory removed. Of 500 candidates, 420 qualified. 80 stayed, and rightly so: every one of them held unsaved work.
Second: a browser profile is a login, not a cache. The playwright-linkedin directory is the agent's connection to LinkedIn. Deleting it means someone signs in again by hand, with two-factor prompts and anti-bot checks. So we deleted only the cache folders inside each profile — Cache, Code Cache, GPUCache, the Service Worker cache — and never touched cookies, Local Storage or IndexedDB. Any profile a browser currently had open was skipped entirely.
What is safe to delete, and what is not
The rule that emerged is simple: delete only what regenerates itself or already exists somewhere else.
- Xcode DerivedData — yes, but never while a build is running.
- Plugin-install clones older than a day — yes.
- Cache folders inside browser profiles — yes. Login state — never.
- Re-downloadable model caches (whisper, for example) — yes, if no process is using them.
- Git worktrees — only if old, clean, not in use, and every commit is already on the remote.
- iOS Simulators, device-support files for the paired phone, anything under the system's System or Library — no.
- sudo — never. Nothing on the list needs administrator rights, and that is exactly the sign the list is right.
The daily routine
A one-off cleanup solves nothing — the agents keep working tomorrow and the disk fills again. So we wrote those rules as a script and set up a LaunchAgent that runs it every night at 04:30 at low priority, with a log that records what was removed, what was kept, and why.
The first run: 420 worktrees removed, 133 GB back, 80 directories kept with the reason next to each one. Together with the other categories, the machine went from 16 GB free to 219 GB the same morning. And we lowered cleanupPeriodDays to 14 so session transcripts never pile up beyond two weeks.
Three traps we hit along the way, worth knowing about:
- launchd does not give your script a PATH. A script that works in Terminal fails silently when scheduled, because launchd does not know the Homebrew directories and sometimes not even
/usr/sbin. The fix: an explicit PATH in the plist, and absolute paths for every system command. - In a linked worktree,
.gitis a file, not a directory. The common test[ -d .git ]returns false on exactly the directories we wanted to recognise. - Squash merges land the content on the main branch without the original commit becoming an ancestor of it. An "is the commit on the remote" check alone would have kept dozens of directories that were already merged. So we also check against the list of merged pull requests.
And now it is a plugin
Because we run agents on more than one machine — and because this is a problem everyone who runs Claude Code seriously will meet — we packaged the routine as an open-source plugin called mac-agent-hygiene. It ships an MCP server with four tools: hygiene_status to read the state, hygiene_plan for a dry run that lists every removal candidate with its reason, hygiene_apply that removes only what was planned and explicitly confirmed, and hygiene_schedule that installs the daily run. When you run it yourself, nothing is deleted without a plan and a confirm; the nightly run applies exactly the same rules automatically. Either way, every item is re-checked at the moment of removal.
Installing it is two commands in Claude Code:
/plugin marketplace add MSApps-Mobile/claude-plugins
/plugin install mac-agent-hygiene@msapps-plugins
The plugin, like the rest of our open-source plugins, is documented at claudeservices.ai/plugins, and the code lives on GitHub. If this is your first look at our marketplace, we also wrote about the other plugins and what they do.
What to take from this
A machine that agents work on fills up in ways that look nothing like a person's computer, and the usual tools cannot see them. The right order is always the same: measure, understand what is safe, delete only that — and then make it a routine that does not depend on anyone's memory. At MSApps, a Claude Partner Network member led by a Claude Certified Architect, we have been building and operating a fleet of Claude agents in production for months, and lessons like this one are exactly what we bring to client projects.
Want us to look at your environment or the agents you are planning? Talk to us or message us on WhatsApp.